SHARE
Facebook X Pinterest WhatsApp

New Linux Malware Surges, Surpassing Android

Linux malware is skyrocketing and now surpasses both macOS and Android, according to a new report, suggesting that cybercriminals are increasingly targeting the open source operating system. The Atlas VPN report said the number of new Linux malware samples collected soared by 646% from the first half of 2021 to the first half of 2022, […]

Written By
thumbnail Julien Maury
Julien Maury
Aug 2, 2022
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Linux malware is skyrocketing and now surpasses both macOS and Android, according to a new report, suggesting that cybercriminals are increasingly targeting the open source operating system.

The Atlas VPN report said the number of new Linux malware samples collected soared by 646% from the first half of 2021 to the first half of 2022, from 226,334 samples to nearly 1.7 million.

While the growth has stabilized since hitting a record in the fourth quarter of 2021, the first six months of 2022 have already seen more new Linux malware than all of 2021.

The Linux malware growth has occurred even as Windows, Android and macOS have all seen a decline in new malware samples. Windows still leads overall due to its commanding market share, accounting for 41.4 million malware samples in the first half of 2022.

Citing Statcounter Global Stats, Atlas VPN said Android has a 44% share of the overall operating systems market, while Windows and OS X have 29% and 6%, respectively.

Linux has just 1% of the OS market, but Atlas VPN noted, “while Linux is not as popular among computer users as other operating systems, it runs the back-end systems of many networks, making attacks on Linux highly lucrative. As Linux adoption rises, so will attacks against it.”

Linux powers many cloud-based architectures, and most IoT devices run very minimalist Linux distributions that consist of a Linux kernel and a few core functions, making them attractive for botnets and other similar campaigns.

Considering the value in enterprise targets, hackers are also developing more sophisticated Linux malware (see New Highly-Evasive Linux Malware Infects All Running Processes).

The Atlas VPN team used AV-ATLAS, a threat intelligence platform from AV-TEST Gmb, for its report.

See the Best Open Source Security Tools

How to Protect Against Linux Malware

Some Linux malware, such as Symbiote or more recently OrBit, are particularly evasive and thus pretty hard to detect and remove. Hackers master Linux internals and the current trend is stealth.

More than ever, monitoring all endpoints, including Linux-based systems, is essential. Users and administrators must also update their devices or, at least, apply all security patches, even if it gets harder to keep pace.

Attackers may use Linux malware to harvest credentials or exfiltrate information. Companies should not neglect such post-exploitation tactics, as ransomware groups not only encrypt the victim’s files these days but also use exfiltrated data as a means of extortion.

In that perspective, additional layers of protection like data-in-use encryption might help prevent such events.

Read next: Exfiltration Can Be Stopped With Data-in-Use Encryption, Company Says

thumbnail Julien Maury

eSecurity Planet contributor Julien Maury writes about penetration testing, code security, open source security and more. He is a backend developer, a mentor and a technical writer who enjoys sharing his knowledge and learning new concepts.

Recommended for you...

Denial of Fuzzing: Rust-Safe Code Triggers Kernel Crashes in Windows
Ken Underhill
Oct 17, 2025
Microsoft Warns: Ransomware Powers Most Cyberattacks
Ken Underhill
Oct 17, 2025
North Korean Hackers Use Blockchain to Hide Crypto-Stealing Malware
Ken Underhill
Oct 17, 2025
CISA Warns of Critical Vulnerability in Adobe Experience Manager Forms
Ken Underhill
Oct 17, 2025
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.