Williams said the best way to forensically examine a suspect USB drive is by plugging the device into an isolated Linux-based computer that doesn’t automatically mount the drive to the operating system. “We would then create a forensic image of the USB and extract any malware for analysis in the lab,” he said. “While there is still a very small risk that the malware targets Linux, that’s not the normal case.” That's…
> While there is still a very small risk that the malware targets Linux I found that statement surprising. For industrial or nation state spionage I would expect people to target linux in 2019
Also keep in mind that the most likely accessible targets would be end user type machines, in that area I'd understand if you carry something exploiting a Mac but Linux? That's just virtual dead weight.