Aren't malware nowadays targetting the home directory? with so many users installing executables, language interpreters or cloud management binaries in their homedir I wouldn't even bother trying to elevate privileges and/or infect /usr if I was writing a malware. Especially as all the interesting parts that are worth being stolen are also in the homedir.