Excluding straight vandalism, I can't really come up with another reason for the reported sequence of events. Presumably the first attacker wanted to build a botnet (which is actually something they can draw profit from), and a competitor wanted to prevent them from doing that.
Otherwise — again, excluding straight vandalism — what is the benefit of wiping the devices? Having your preexisting botnet target/scan and exploit these devices isn't free. What else could they have been trying to gain?