Hi,
From my understanding, IoT devices are not complicated as other devices, such as PC, in other words, we are not able to install the anti-virus software on the IoT devices, which leads the IoT devices to be more attackable.
Also, you can refer to the conclusions below:
1) Simple hardware structure, lack of safety protection circuit, easy to be attacked by side-channel, etc.;
2) The design of the mobile phone is simple, and it is easy to be tampered with maliciously;
3) The interaction of various applications is complex, the devices are connected through the network, there are many intermediates, the communication protocol is simple, and it is easy to be susceptible to malicious software such as house Trojan horses;