Malware vs Ransomware
Malware
115
statistics from 53 sources
Ransomware
1,216
statistics from 113 sources
Latest Malware
Organisations are most comfortable authorising autonomous agents for threat intelligence enrichment and correlation (49%), phishing email quarantine or deletion (47%), and malware removal and system remediation (46%).
TsarBot targeted 450 banking apps and accounted for 58% of its global activity.
CopyBara targeted 446 banking apps.
Nexus concentrated 90% of its global targets in EMEA.
Firewalls are the most widely adopted measure (92%) among manufacturers, followed by malware protection (80%), secure configuration (67%) and access controls (61%).
Malware activity averaged 39,341 hits per firewall in the first half of 2026, giving financial services the second-highest per-device malware intensity of any industry, behind only healthcare.
Ten ransomware families were active against the financial services sector in the first half of 2026, including REvil (Sodinokibi) and Prometheus.
11% of the top 100 vendors most commonly used by universities currently show evidence of active infostealer malware infections.
IT and security professionals rate attackers using AI to generate self-mutating malware as a high or extreme risk at 55.9%, employees leaking sensitive data into public LLMs at 53.5%, AI-driven evasion techniques at 52.5%, and deepfakes or voice cloning used in fraud or BEC at 51.9%.
1 in 7 of Austrailian SME owners or managers reported malware.
33.9% of Australian SME owners or managers reported experiencing malware.
67.3% of the 832 malicious accounts banned between March 2025 and March 2026 used AI to write malware.
Across organizations in Europe, GitHub and Microsoft OneDrive are the most abused platforms for malware distribution, each impacting 10% of organizations.
56 malicious extensions were identified on OpenVSX.
495 malicious AI models were identified on Hugging Face.
Latest Ransomware
Cloud-related threats (40%), third-party breaches (34%), and ransomware (33%) rank after AI as major preparedness gaps.
49% of organizations that experienced or suspected a deepfake attack also experience follow-on cyberattacks such as ransomware.
Ransomware attacks on manufacturers have more than doubled since 2023.
The average manufacturing or distribution ransomware victim scores 0.552 on the RSI.
In the first half of 2026, ransomware attacks on manufacturers increased nearly 40% year over year.
83% of organizations fell victim to a successful ransomware attack in the last 24 months, up from 66% in 2024.
Of organizations hit by ransomware, 75% experience multiple service interruptions.
83% of technology leaders view backup storage as the last line of defense against ransomware.
Twelve vulnerabilities carry confirmed "multi-nexus" attribution, being independently exploited across five distinct threat categories (China, Russia, DPRK, Iran-nexus, and criminal actors).
More than half of mid-market ransomware victims generate less than $50M in annual revenue.
Mid-market organizations accounted for approximately 72–75% of ransomware victims each year.
Compromised credentials accounted for 67% of ransomware intrusions investigated by Beazley Security, down from 74% in Q1.
Public ransomware leak-site postings totaled 2,268, remaining nearly 60% above Q2 2025.
73% of ransomware attacks in North America and Europe hit companies with $10M to $1B in annual revenue from 2023 through the first half of 2026.
27% of healthcare organizations cite cybersecurity threats and ransomware as the #1 network challenge, 23% cite staffing shortages and lack of expertise, 20% cite rising operational and compliance costs, 16% cite network reliability impacting clinical systems, and 15% cite aging or fragmented infrastructure.