My understanding is that the MIPS part is the one that targets routers. An infected router will then infect machines that connect to it with trojans built for their respective architecture. (And the trojan is called gobeacon in the case of linux.)
Really not a security person so a lot of this is above my head.
malware that takes full control of connected devices running Windows, macOS, and Linux
And further down:
Once installed, ZuoRAT enumerates the devices connected to the infected router. The threat actor can then use DNS hijacking and HTTP hijacking to cause the connected devices to install other malware. Two of those malware pieces—dubbed CBeacon and GoBeacon—are custom-made, with the first written for Windows in C++ and the latter written in Go for cross-compiling on Linux and macOS devices.
I find the article makes it sound like gobeacon was specifically written for Linux and MacOS. Maybe it’s overly dramatic, i don’t know.
Indeed the graphic you copied has this “Windows Loader” part. But the text mentions Linux. I don’t think i should assume i am safe just because i don’t use Windows.
I connect to a lot of different routers with my laptop. Making sure i am never connecting to a problematic router is not really an option.
I will take it as “the article is overly dramatic and Linux is still too niche a target for me to have to worry about this”. But it is definitely not something i can have an authoritative opinion on.