Malware targeting Linux-based operating systems, commonly used in IoT devices, rose 35% YoY in 2021; three malware families accounted for 22%+ of total threats
Mihai Maganu / CrowdStrike Blog :
Context & Ripple Effects
CrowdStrike's 2021 numbers land on an old pattern: researchers flagged router and IoT attack vectors back in 2018, when MikroTik and TP-Link devices topped the list of most-compromised gear, and oddities like the self-patching Linux.WiFatch worm showed years earlier that embedded Linux was already a working malware habitat. The new datapoint is scale — a 35% YoY rise with threat volume concentrating in just three families.
The longer arc cuts both ways. Later finds like the stealthy Shikitega strain confirmed Linux IoT malware kept maturing after this report, while CrowdStrike's own follow-up research found 79% of 2024 intrusions were malware-free, up from 40% in 2019 — meaning the malware-heavy era this article documents was already giving way to phishing-led access on mainstream targets.
First-order effects
- Operators of large fleets of Linux-based devices — router vendors like MikroTik and TP-Link that topped the 2018 compromise rankings — face direct pressure to patch, since three families alone drive over 22% of the threat volume they must detect.
- Security teams get a prioritization shortcut: with threat concentration this high, signature coverage for a handful of Linux malware families buys disproportionate protection across IoT estates.
Second-order effects
- As defenders concentrate on the dominant families, attackers are pushed toward stealthier strains like Shikitega or away from malware entirely — consistent with CrowdStrike's later finding that voice phishing overtook email phishing as the main first-access method.
- Device vendors' slow patch cadence for embedded Linux becomes a competitive liability, pushing buyers toward vendors offering signed firmware updates and longer support windows.
Third-order effects
- If the pattern holds, embedded Linux becomes the last major reservoir of classic malware while human-targeted intrusion goes malware-free — splitting the security market between endpoint AV for device fleets and identity/phishing defense for people.
- Unpatchable IoT fleets at scale strengthen the case for regulation mandating update commitments for connected devices, since the 2018-era attack vectors persist precisely because fielded hardware never gets fixed.
The trend: Malware is consolidating around always-on, rarely-patched Linux devices even as intrusion tradecraft against mainstream targets abandons malware for social engineering.