/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Malware targeting Linux-based operating systems, commonly used in IoT devices, rose 35% YoY in 2021; three malware families accounted for 22%+ of total threats

Mihai Maganu / CrowdStrike Blog :

CrowdStrike Blog Mihai Maganu

Context & Ripple Effects

CrowdStrike's 2021 numbers land on an old pattern: researchers flagged router and IoT attack vectors back in 2018, when MikroTik and TP-Link devices topped the list of most-compromised gear, and oddities like the self-patching Linux.WiFatch worm showed years earlier that embedded Linux was already a working malware habitat. The new datapoint is scale — a 35% YoY rise with threat volume concentrating in just three families.

The longer arc cuts both ways. Later finds like the stealthy Shikitega strain confirmed Linux IoT malware kept maturing after this report, while CrowdStrike's own follow-up research found 79% of 2024 intrusions were malware-free, up from 40% in 2019 — meaning the malware-heavy era this article documents was already giving way to phishing-led access on mainstream targets.

First-order effects

  • Operators of large fleets of Linux-based devices — router vendors like MikroTik and TP-Link that topped the 2018 compromise rankings — face direct pressure to patch, since three families alone drive over 22% of the threat volume they must detect.
  • Security teams get a prioritization shortcut: with threat concentration this high, signature coverage for a handful of Linux malware families buys disproportionate protection across IoT estates.

Second-order effects

  • As defenders concentrate on the dominant families, attackers are pushed toward stealthier strains like Shikitega or away from malware entirely — consistent with CrowdStrike's later finding that voice phishing overtook email phishing as the main first-access method.
  • Device vendors' slow patch cadence for embedded Linux becomes a competitive liability, pushing buyers toward vendors offering signed firmware updates and longer support windows.

Third-order effects

  • If the pattern holds, embedded Linux becomes the last major reservoir of classic malware while human-targeted intrusion goes malware-free — splitting the security market between endpoint AV for device fleets and identity/phishing defense for people.
  • Unpatchable IoT fleets at scale strengthen the case for regulation mandating update commitments for connected devices, since the 2018-era attack vectors persist precisely because fielded hardware never gets fixed.

The trend: Malware is consolidating around always-on, rarely-patched Linux devices even as intrusion tradecraft against mainstream targets abandons malware for social engineering.

Discussion

  • @crowdstrike @crowdstrike on x
    @CrowdStrike has observed that malware targeting Linux-based systems increased by 35% in 2021. XorDDoS, Mirai and Mozi were the most common malware families. Learn more: ⬇️ https://www.crowdstrike.com/ ...