CSIDB logo
Threat actor

Janitor

Attribution profile

Type
Hacker
Location
Russia
Known incidents
0 incidents
Sources
1 source
First seen
-
Last seen
-
Updated
2026-07-30 21:59
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Janitor, also known by the alias Janit0r, is a threat actor identified as being based in Russia who claims authorship of the BrickerBot malware family targeting insecure Internet of Things devices. He describes BrickerBot as a tool that first attempts to secure a compromised device; if the device cannot be secured or the attempt fails, the malware wipes the device’s flash storage and overwrites it with random data, rendering the hardware unusable and requiring repair or replacement. Janitor states that he created BrickerBot to focus on the same classes of IoT devices that are commonly exploited by other malware families such as Mirai, Hajime, Wifatch, Gafgyt, and Imeij, indicating a strategic objective of causing disruption rather than financial gain or espionage. His activity centers on exploiting weak management interfaces, particularly the TR‑069 protocol, which he notes has known security flaws and has been abused by Mirai in prior incidents affecting Deutsche Telekom and British ISPs. The malware’s tooling style includes multiple versions with differing bricking techniques, as later revealed in reports from Radware that highlighted newer iterations of BrickerBot discovered over a weekend following the Sierra Tel event.

Janitor brought the BrickerBot activity to public attention during the April 2017 outage experienced by Californian ISP Sierra Tel, where customers lost Internet and telephone service due to compromised Zyxel HN‑51 modems. He told Bleeping Computer that BrickerBot was active on Sierra Tel’s network at the time the outage was reported, although he also suggested that a concurrent Mirai infection might have contributed to the disruption. Sierra Tel acknowledged a malicious hacking event targeting the HN‑51 modems and worked with law enforcement to identify the perpetrator, while Janitor praised the ISP’s transparency but criticized its failure to filter TR‑069 access from the WAN. No public evidence links Janitor to a state sponsor or a criminal consortium; his known affiliation remains limited to his self‑identified location in Russia and his role as the purported developer of BrickerBot. The Sierra Tel incident stands as a representative operation illustrating his use of IoT‑focused malware to cause widespread service disruption through device bricking.

Incidents

Attributed incidents are available to members.

0 incidents

Sources

Sources available to members: 1 source.

CSIDB