Linux.MulDrop.14 is a Linux worm that seeks out networked Raspberry Pi systems with default root passwords; after taking them over and ZMap and sshpass, it begins mining an unspecified cryptocurrency, creating riches for the malware's author and handing you the power-bill.
In this world exist idiots whom use default passwords?
This is symptomatic of IoT devices in general. People just don't realize that these small devices are full-fledged computers which can be used to do all sorts of things.
I think peoplpe who buy this computers can change root passwords easy :)
Can, yes. Will they, maybe not.
I always do that. Otherwise no sense use Linux at all.