Malware vs Ransomware
Malware
119
statistics from 52 sources
Ransomware
1,199
statistics from 111 sources
Latest Malware
TsarBot targeted 450 banking apps and accounted for 58% of its global activity.
CopyBara targeted 446 banking apps.
Hook targeted 385 banking apps.
Firewalls are the most widely adopted measure (92%) among manufacturers, followed by malware protection (80%), secure configuration (67%) and access controls (61%).
Malware activity averaged 39,341 hits per firewall in the first half of 2026, giving financial services the second-highest per-device malware intensity of any industry, behind only healthcare.
Ten ransomware families were active against the financial services sector in the first half of 2026, including REvil (Sodinokibi) and Prometheus.
11% of the top 100 vendors most commonly used by universities currently show evidence of active infostealer malware infections.
IT and security professionals rate attackers using AI to generate self-mutating malware as a high or extreme risk at 55.9%, employees leaking sensitive data into public LLMs at 53.5%, AI-driven evasion techniques at 52.5%, and deepfakes or voice cloning used in fraud or BEC at 51.9%.
1 in 7 of Austrailian SME owners or managers reported malware.
33.9% of Australian SME owners or managers reported experiencing malware.
67.3% of the 832 malicious accounts banned between March 2025 and March 2026 used AI to write malware.
Across organizations in Europe, GitHub and Microsoft OneDrive are the most abused platforms for malware distribution, each impacting 10% of organizations.
495 malicious AI models were identified on Hugging Face.
969 malicious AI agent skills were identified carrying high-impact payloads.
56 malicious extensions were identified on OpenVSX.
Latest Ransomware
Big game hunting adversaries named 572 technology entities on dedicated leak sites for extortion.
Twelve vulnerabilities carry confirmed "multi-nexus" attribution, being independently exploited across five distinct threat categories (China, Russia, DPRK, Iran-nexus, and criminal actors).
Compromised credentials accounted for 67% of ransomware intrusions investigated by Beazley Security, down from 74% in Q1.
Public ransomware leak-site postings totaled 2,268, remaining nearly 60% above Q2 2025.
73% of ransomware attacks in North America and Europe hit companies with $10M to $1B in annual revenue from 2023 through the first half of 2026.
Mid-market organizations accounted for 74.6% of ransomware incidents in 2023, 72.1% in 2024, 74% in 2025, and 72.3% in the first half of 2026.
More than half of mid-market ransomware victims generate less than $50M in annual revenue.
27% of healthcare organizations cite cybersecurity threats and ransomware as the #1 network challenge, 23% cite staffing shortages and lack of expertise, 20% cite rising operational and compliance costs, 16% cite network reliability impacting clinical systems, and 15% cite aging or fragmented infrastructure.
Professional services recorded 69.9 million ransomware hits in the first half of 2026, more than any other vertical.
Ten active ransomware families operated simultaneously against the professional services sector in the first half of 2026, including Filecoder (19.1 million hits across 113 organizations), Gandcrab (11.9 million) and Ryuk (10.5 million).
460 organizations in the professional services sector are actively detecting ransomware campaigns, representing the broadest exposure of any vertical.
Ransomware remained the most persistent and disruptive cyber threat to industrial organizations in Q2 2026
Manufacturing was the most affected sector by ransomware incidents affecting industrial organizations worldwide, with 747 incidents (65%) across all subsectors in Q2 2026.
ICS-related organizations (engineering firms, system integrators, and equipment manufacturers) accounted for the second-most-impacted sector by ransomware incidents ffectign industrial organizations worldwide, with 117 incidents in Q2 2026.
7% of reported cybercrime cases in Africa in 2025 involved ransomware or Banking Trojan stealers.