/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Overview of the most popular attack vectors against IoT devices and which are most often compromised: MikroTik devices top the list, followed by TP-Link

Cybercriminals' interest in IoT devices continues to grow: in H1 2018 we picked up three times as many malware samples attacking smart devices as in the whole of 2017.

Securelist

Context & Ripple Effects

Securelist's H1 2018 tally — three times as many smart-device malware samples as all of 2017 — lands mid-arc in a documented escalation. The prior years' coverage shows the groundwork: Linux.WiFatch quietly spreading across tens of thousands of routers in 2015, then a 2016 report on over 4.5M appliances exposed through reused private keys for HTTPS and SSH.

The ranking itself was quickly validated: within months of this report, researchers counted 415K+ infected routers worldwide, a majority of them MikroTik, running cryptominers like CoinHive and Omine. MikroTik topping the list here is not a one-off finding but the leading edge of a pattern.

First-order effects

  • MikroTik and TP-Link owners are the immediately exposed population — these two brands sit atop the compromise list, meaning their installed base is where attacker tooling is concentrated right now.
  • The sample-volume tripling signals defenders' detection pipelines need retooling: threat feeds built around 2017-era volumes undercount the active IoT malware population.

Second-order effects

  • MikroTik's dominance among compromised devices forces it into a patch-and-harden race against its own user base, while the December cryptomining wave shows attackers monetizing the same footholds at scale.
  • TP-Link, ranked second, faces the same pressure one step behind — vendor security posture becomes a purchasing criterion for consumers and ISPs choosing CPE hardware.

Third-order effects

  • Consumer-grade routers are consolidating as persistent infrastructure rather than incidental victims — a trajectory that runs from profit-driven miners in 2018 to the UK's 2026 attribution of APT28 hijacking MikroTik and TP-Link routers for credential theft and traffic redirection.
  • If the volume trend holds, the industry's structural answer shifts from per-device patching toward carrier-managed and auto-updating home gateways, squeezing unmanaged consumer router vendors out of sensitive deployments.

The trend: IoT device compromise is scaling from opportunistic criminal malware into strategic infrastructure exploited by both profit-driven and state-backed actors, with router vendors' security defaults setting the blast radius.