Malware vs Ransomware

Malware

108

statistics from 51 sources

Ransomware

1,181

statistics from 109 sources

Latest Malware

Malware activity averaged 39,341 hits per firewall in the first half of 2026, giving financial services the second-highest per-device malware intensity of any industry, behind only healthcare.

MalwareCybersecurityFinancial Services

Ten ransomware families were active against the financial services sector in the first half of 2026, including REvil (Sodinokibi) and Prometheus.

RansomwareFinancial ServicesMalware

11% of the top 100 vendors most commonly used by universities currently show evidence of active infostealer malware infections.

MalwareCredential TheftHigher EducationInfostealerThird-Party Supply Risk

IT and security professionals rate attackers using AI to generate self-mutating malware as a high or extreme risk at 55.9%, employees leaking sensitive data into public LLMs at 53.5%, AI-driven evasion techniques at 52.5%, and deepfakes or voice cloning used in fraud or BEC at 51.9%.

AI Self-Mutating MalwareMalware

1 in 7 of Austrailian SME owners or managers reported malware.

Australian Institute of CriminologyCybercrime in Australia 2025·1mo ago
AustraliaSMEMalwareReporting

33.9% of Australian SME owners or managers reported experiencing malware.

Australian Institute of CriminologyCybercrime in Australia 2025·1mo ago
AustraliaSMEMalware

67.3% of the 832 malicious accounts banned between March 2025 and March 2026 used AI to write malware.

MalwareAI in Cybercrime

Across organizations in Europe, GitHub and Microsoft OneDrive are the most abused platforms for malware distribution, each impacting 10% of organizations.

Malware DistributionMicrosoft OneDriveGitHubEurope

495 malicious AI models were identified on Hugging Face.

Malicious AI ModelsMalware

969 malicious AI agent skills were identified carrying high-impact payloads.

AI SecurityAgentic ToolsMalicious AI Agent SkillsMalware

56 malicious extensions were identified on OpenVSX.

MalwareMalicious Extensions

The most prevalent malware families observed in 2025 are Cobalt Strike, Sliver, Metasploit, Burp, PlugX, SuperShell C2, Havoc, Panda C2, Brute Ratel, and ShadowPad.

Malware Cobalt StrikeSliverMetasploitBurp

Credential-stealer infections were dominated by RedLine with 911,968 infections (50.80%), Lumma with 499,784 infections (27.84%), and Vidar with 236,778 infections (13.19%).

MalwareCredential TheftInfostealer

The majority of businesses and charities have implemented basic technical controls, such as updated malware protection (81% businesses and 63% charities), backing up data securely via a cloud service (74% businesses and 57% charities), password policies (74% businesses and 56% charities), network firewalls (74% businesses and 45% charities) and restricted admin rights (73% businesses and 65% charities).

Department for Science, Innovation & TechnologyCyber security breaches survey 2025/2026·3mo ago
UKSecurity controlsMalware ProtectionCloudPassword Policies

46% of IT security professionals report that AI is contributing to a rise in adaptive and evasive malware.

CyberEdge GroupCyberthreat Defense Report·3mo ago
Evasive MalwareAdaptive MalwareCybersecurity ThreatsAI
View all Malware

Latest Ransomware

Big game hunting adversaries named 572 technology entities on dedicated leak sites for extortion.

ExtortionRansomwareTechnology Sector

Professional services recorded 69.9 million ransomware hits in the first half of 2026, more than any other vertical.

RansomwareProfessional Services

Ten active ransomware families operated simultaneously against the professional services sector in the first half of 2026, including Filecoder (19.1 million hits across 113 organizations), Gandcrab (11.9 million) and Ryuk (10.5 million).

RansomwareProfessional Services

460 organizations in the professional services sector are actively detecting ransomware campaigns, representing the broadest exposure of any vertical.

RansomwareProfessional Services

7% of reported cybercrime cases in Africa in 2025 involved ransomware or Banking Trojan stealers.

AfricaRansomwareBanking Trojan Stealers

The highest ransom demand in Q2 2026 was $25 million.

Ransom DemandsRansomware

Qilin accounted for 285 undisclosed attacks (14%), The Gentlemen accounted for 219 (11%), and Dragon Force accounted for 137 (7%) in Q2 2026.

Threat ActorsRansomwareQilinThe GentlemenDragon Force

The number of undisclosed ransomware attacks fell 6% compared to the previous quarter.

RansomwareThreat Trends

41% of ransomware attacks exploited brand reputation.

RansomwareExtortion

35% of ransomware attacks exploited employee data.

RansomwareExtortionSensitive Data

31% of ransomware attacks exploited intellectual property.

RansomwareExtortionIntellectual Property

Ransomware incidents made up over 20% of Cisco Talos Incident Response engagements this quarter, similar to just under 20% last quarter.

Cisco TalosIR Trends Q2 2026·3w ago
RansomwareIncident Response

Threat actors maintained undetected access for approximately three days before ransomware deployment in the observed Sinobi engagement.

Cisco TalosIR Trends Q2 2026·3w ago
RansomwarePersistenceIncident Response

Q2 2026 recorded 1,988 ransomware attack claims from 89 groups across 101 countries.

Ransomware

The US accounted for 42.5% of ransomware claims, Canada for 5% and Germany for 4.8%.

RansomwareUSCanadaGermany
View all Ransomware