Overview of the most popular attack vectors against IoT devices and which are most often compromised: MikroTik devices top the list, followed by TP-Link
Cybercriminals' interest in IoT devices continues to grow: in H1 2018 we picked up three times as many malware samples attacking smart devices as in the whole of 2017.
Context & Ripple Effects
Securelist's H1 2018 tally — three times as many smart-device malware samples as all of 2017 — lands mid-arc in a documented escalation. The prior years' coverage shows the groundwork: Linux.WiFatch quietly spreading across tens of thousands of routers in 2015, then a 2016 report on over 4.5M appliances exposed through reused private keys for HTTPS and SSH.
The ranking itself was quickly validated: within months of this report, researchers counted 415K+ infected routers worldwide, a majority of them MikroTik, running cryptominers like CoinHive and Omine. MikroTik topping the list here is not a one-off finding but the leading edge of a pattern.
First-order effects
- MikroTik and TP-Link owners are the immediately exposed population — these two brands sit atop the compromise list, meaning their installed base is where attacker tooling is concentrated right now.
- The sample-volume tripling signals defenders' detection pipelines need retooling: threat feeds built around 2017-era volumes undercount the active IoT malware population.
Second-order effects
- MikroTik's dominance among compromised devices forces it into a patch-and-harden race against its own user base, while the December cryptomining wave shows attackers monetizing the same footholds at scale.
- TP-Link, ranked second, faces the same pressure one step behind — vendor security posture becomes a purchasing criterion for consumers and ISPs choosing CPE hardware.
Third-order effects
- Consumer-grade routers are consolidating as persistent infrastructure rather than incidental victims — a trajectory that runs from profit-driven miners in 2018 to the UK's 2026 attribution of APT28 hijacking MikroTik and TP-Link routers for credential theft and traffic redirection.
- If the volume trend holds, the industry's structural answer shifts from per-device patching toward carrier-managed and auto-updating home gateways, squeezing unmanaged consumer router vendors out of sensitive deployments.
The trend: IoT device compromise is scaling from opportunistic criminal malware into strategic infrastructure exploited by both profit-driven and state-backed actors, with router vendors' security defaults setting the blast radius.