I have always heard not to use antivirus on Linux but I saw the post about a guy getting a RAT exploit backdoored through wine and it had me thinking should I be using ClamAV or some other antivirus for Linux?

  • iByteABit@lemmy.ml
    link
    fedilink
    arrow-up
    7
    ·
    21 hours ago

    Quoted from the Arch wiki:

    The current situation of anti-malware products on Linux is inadequate due to several factors:
    
        - Limited Variety: Compared to Windows, there are fewer users/clients resulting in limited interest for companies to develop products for Linux.
    
        - Complacency: Many believe Linux is inherently secure, leading to a lack of awareness and focus on malware protection. This creates a gap in proactive defense mechanisms.
    
        - Lack of Features: Existing tools often lack advanced features which are common in Windows anti-malware products, making them less effective on Linux.
    
    This is especially bad because the amount of malware on Linux is increasing just as the possible attack surface due to the increasing number of Linux-based servers and IoT devices.
    Currently on Linux one of the few existing and actively developed anti-malware solutions is ClamAV.
    

    There is no inherent mechanism that makes your system secure to viruses just because it’s Linux. This is mostly said because, Linux being a small percentage of desktop users, it’s not yet common for hackers to target Linux systems because it’s not worth the hassle when you can just target a much larger audience on Windows that is on average much less tech literate too.

    But as Linux popularity grows, viruses will start popping up on Linux as well, so it’s never a bad idea to use ClamAV. You are already more protected when you use package repositories instead of downloading executables from websites like you do on Windows, and Linux has better file system permissions, but you still need to be careful what you’re downloading and running.

    • MonkderVierte@lemmy.zip
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      21 hours ago

      It also apllies some security practices by default, like not executable by default, mime type detection of files (no document.pdf.exe), which does make a linux desktop more safe.

      And safety is always a compromise with practicability. For example, Linux-hardened.

      But sure, there’s always room for improvement.