Malware Statistics

115 stats53 sources

Latest Statistics

Organisations are most comfortable authorising autonomous agents for threat intelligence enrichment and correlation (49%), phishing email quarantine or deletion (47%), and malware removal and system remediation (46%).

AI AutonomyThreat IntelligencePhishingMalwareSystem Remediation

TsarBot targeted 450 banking apps and accounted for 58% of its global activity.

TsarBotMobile MalwareBanking FraudBanking AppsFinancial Services

CopyBara targeted 446 banking apps.

CopyBaraMobile MalwareBanking FraudBanking AppsFinancial Services

Nexus concentrated 90% of its global targets in EMEA.

NexusMobile MalwareEMEAFinancial Services

Firewalls are the most widely adopted measure (92%) among manufacturers, followed by malware protection (80%), secure configuration (67%) and access controls (61%).

ManufacturingUKFirewallsMalware ProtectionAccess Controls

Malware activity averaged 39,341 hits per firewall in the first half of 2026, giving financial services the second-highest per-device malware intensity of any industry, behind only healthcare.

MalwareCybersecurityFinancial Services

Ten ransomware families were active against the financial services sector in the first half of 2026, including REvil (Sodinokibi) and Prometheus.

RansomwareFinancial ServicesMalware

11% of the top 100 vendors most commonly used by universities currently show evidence of active infostealer malware infections.

MalwareCredential TheftHigher EducationInfostealerThird-Party Supply Risk

IT and security professionals rate attackers using AI to generate self-mutating malware as a high or extreme risk at 55.9%, employees leaking sensitive data into public LLMs at 53.5%, AI-driven evasion techniques at 52.5%, and deepfakes or voice cloning used in fraud or BEC at 51.9%.

AI Self-Mutating MalwareMalware

1 in 7 of Austrailian SME owners or managers reported malware.

Australian Institute of CriminologyCybercrime in Australia 2025·3mo ago
AustraliaSMEMalwareReporting

33.9% of Australian SME owners or managers reported experiencing malware.

Australian Institute of CriminologyCybercrime in Australia 2025·3mo ago
AustraliaSMEMalware

67.3% of the 832 malicious accounts banned between March 2025 and March 2026 used AI to write malware.

MalwareAI in Cybercrime

Across organizations in Europe, GitHub and Microsoft OneDrive are the most abused platforms for malware distribution, each impacting 10% of organizations.

Malware DistributionMicrosoft OneDriveGitHubEurope

56 malicious extensions were identified on OpenVSX.

MalwareMalicious Extensions

495 malicious AI models were identified on Hugging Face.

Malicious AI ModelsMalware

969 malicious AI agent skills were identified carrying high-impact payloads.

AI SecurityAgentic ToolsMalicious AI Agent SkillsMalware

The most prevalent malware families observed in 2025 are Cobalt Strike, Sliver, Metasploit, Burp, PlugX, SuperShell C2, Havoc, Panda C2, Brute Ratel, and ShadowPad.

Malware Cobalt StrikeSliverMetasploitBurp

Credential-stealer infections were dominated by RedLine with 911,968 infections (50.80%), Lumma with 499,784 infections (27.84%), and Vidar with 236,778 infections (13.19%).

MalwareCredential TheftInfostealer

The majority of businesses and charities have implemented basic technical controls, such as updated malware protection (81% businesses and 63% charities), backing up data securely via a cloud service (74% businesses and 57% charities), password policies (74% businesses and 56% charities), network firewalls (74% businesses and 45% charities) and restricted admin rights (73% businesses and 65% charities).

Department for Science, Innovation & TechnologyCyber security breaches survey 2025/2026·5mo ago
UKSecurity controlsMalware ProtectionCloudPassword Policies

46% of IT security professionals report that AI is contributing to a rise in adaptive and evasive malware.

CyberEdge GroupCyberthreat Defense Report·5mo ago
Evasive MalwareAdaptive MalwareCybersecurity ThreatsAI

Over a quarter of CIOs report AI as a significant source of risk, placing it on par with malware, ransomware and phishing.

LogicalisGlobal CIO Report 2026·5mo ago
AI RiskMalwareRansomwarePhishing

33% of CIOs identify malware and ransomware as dominant threats.

LogicalisGlobal CIO Report 2026·5mo ago
MalwareRansomware

11.01% of organizations have active malicious packages embedded in production environments.

MalwareMalicious Packages

In 2025, more than 90% of open source vulnerability (OSV) malware advisories were reported, a 14x increase over the past two years.

Malware Advisories

BRICKSTORM achieved dwell times of nearly 400 days.

MandiantM-Trends 2026 Report·6mo ago
BRICKSTORMMalwareDwell Time

Enterprise workforces are three times more likely to be targeted with phishing attacks than with infostealer malware.

PhishingInfostealer Malware

There is an average of 50 exposed user credentials per infostealer malware infection.

Infostealer MalwareCredential TheftExposed User Credentials

Malware hidden in public model and code repositories accounts for 35% of AI-related breaches.

HiddenLayerAI Threat Landscape 2026·6mo ago
AI Supply ChainMalwareAI-Related Breaches

Threat actors deployed more than 147,000 malicious domains, nearly 58,000 malware files, and actively exploited 549 vulnerabilities in 2025.

2026 In the Wild Threat ReportHPE·6mo ago
Malicious DomainsMalwareVulnerabilitiesThreat actors

Over 11.1 million machines were infected with infostealers in 2025.

MalwareInfostealers

31% of Americans use anti-malware or antivirus software.

AntivirusAnti-MalwareConsumerUS

17% of adults aged 18–24 use anti-malware protection, versus 50% of adults aged 65 and older.

Anti-MalwareConsumerUS

Across cloud providers, Azure draws 43.5% of observed malware samples, Google Cloud Platform draws 33.2%, and Amazon Web Services draws 23.2%.

DarktraceAnnual Threat Report 2026·7mo ago
Cloud SecurityMalwareAzureGoogle Cloud PlatformAmazon Web Services

Infostealer malware led to the exposure of over 300,000 ChatGPT credentials in 2025.

Identity SecurityCredential TheftInfostealer MalwareChatGPT Credentials

35% of SMB respondents say AI is creating adaptive and evasive malware.

SMBsEvasive MalwareAI

BoaLoader malware is a factor in nearly 20% of incidents observed in the calendar year.

MalwareBoaLoader

41% of internal audit leaders are concerned about the use of AI to insert malicious code.

The Internal Audit Foundation and AuditBoardInternal Audit and AI-Enabled Fraud·7mo ago
MalwareAI FraudInternal Audit

In June 2025, BAUXITE deployed two custom wiper malware variants against Israeli targets.

Wiper MalwareCyber ConflictIsraelBAUXITE

12% of organizations detected employee exposure to malware via GitHub each month in 2025.

MalwareGitHubUser Behavior

In 2025, malicious attachments were present in 18% of phishing attacks.

PhishingMalwarePhishing Techniques