100+ Malware Statistics Your Security Team Must See in 2026

September 18, 2026
by Darshayita Thakur
Darshayita Thakur
DT

Darshayita Thakur

Darshayita Thakur is a Senior SEO Content Specialist at G2 who specializes in SEO and AEO-first, data-forward storytelling. She tests and evaluates a broad range of software products, blending search and discovery strategy, content architecture, and practical analytics to translate data into clear, usable narratives. She emphasizes transparency, measurable impact, and helping buyers navigate toward the right software decisions. When she's not writing, Darshayita reads global and translated literature and delights in uncovering weird historical facts.

Malware, or malicious software, is a big problem for technology users everywhere. The damage it does goes beyond stealing personal information or controlling your device. There are financial losses, too, in fines or resources required to fix it. Every year, malware affects so many people, which costs a lot of money to fix.

Some companies use malware analysis software to isolate and test malicious programs. Others deploy various security solutions to keep malware at bay. For this malware statistics guide, I mapped the data across primary threat research from the organizations that run the telemetry and incident response, paired with G2 Data from verified reviews of the tools built to analyze what they find.

The 100+ malware statistics here cover volume, delivery, ransomware, infostealers, supply chain, AI, cost, sector exposure, and mobile. It will be useful whether you are building a case for detection spend, benchmarking your own incident data, or deciding where the next control belongs.

For each section below, the statistics are drawn directly from original research reports and primary sources. Every figure is dated to the observation window it covers.

How I researched these malware statistics

  • Primary research sources: Verizon 2026 Data Breach Investigations Report, IBM 2026 X-Force Threat Intelligence Index, IBM 2026 Cost of a Data Breach Report, CrowdStrike 2026 Global Threat Report, Microsoft Digital Defense Report 2025, Sophos State of Ransomware 2026, ESET Threat Report H1 2026, Kaspersky Mobile malware evolution 2025, Google Threat Intelligence Group AI Threat Tracker, and AV-TEST. Each source is linked on first mention and listed in full under Sources.
  • G2 review data: I analyzed the G2 Grid Reports for Malware Analysis Tools across four consecutive years, 2023 through 2026, covering satisfaction ratings and likelihood to recommend. G2 Data represents verified reviews from buyers who use the software, aggregated across every product that qualified for each report.
  • Verification: Every external figure was read and confirmed on the source's own published page or report PDF.
  • Date range: Sources published between 2025 and 2026. 

What is the total amount of malware in 2026?

These malware statistics show that the amount of malware has never stopped climbing. What has changed is how little that number tells you on its own. Most samples are short-lived variants of something already known, so the volume figure describes attacker output rather than defender exposure. 

450,000

New malicious programs and potentially unwanted applications are registered every single day, a rate that has made triage capacity, not detection accuracy, the binding constraint.

Source: AV Test

  • From January to early May 2026, Kaspersky detected more than 92,000 attacks disguised as AI agents and services, with over 15,000 unique malware samples identified masquerading as tools such as ChatGPT, Claude and Gemini.  
  • Fake ChatGPT applications accounted for 49% of AI-lure malware attacks detected globally by Kaspersky in the first four months of 2026, with fake Claude and Gemini each representing 18%.
  • Between January and April 2026, Kaspersky blocked more than 33,300 attacks on small and medium-sized businesses where the malware posed as a popular AI service, roughly five times the count from the same four-month period in 2025. 
  • Kaspersky blocked 415,000 attacks on small and medium-sized businesses in January through April 2026 where the malware posed as a messenger or video-conferencing app, including fake versions of Telegram, WhatsApp, Zoom and Microsoft Teams.
  • On average across April to June 2026, 4.54% of users' computers worldwide faced at least one malware web attack.
  • The highest-risk local infection rankings for April to June 2026 show Turkmenistan at 46.38% of users affected and China at 21.92%, against a global average of 10.93%, illustrating how much regional context the global aggregate figure obscures.
  • Microsoft Threat Intelligence detected approximately 7.6 billion email-based phishing threats in April-June 2026, across monthly volumes of 2.7 billion in April, declining to 2.4 billion by June.

Know the threats you’re up against: Explore four common cyberattacks, how they work, and the steps you can take to protect your systems and data.

Want to learn more about Malware Analysis Tools? Explore Malware Analysis Tools products.

How does malware get into an organization?

The malware statistics for the causes of attacks show that the majority of intrusions involved no malicious file at all, running instead on credentials, trusted integrations, and legitimate administrative tooling.

82%

The share of CrowdStrike detections in 2025 that were malware-free, meaning file-based detection alone misses roughly four intrusions in five.

Source: CrowdStrike

    • Exploiting a flaw has overtaken stealing a password. Vulnerability exploitation now accounts for 31% of breaches, surpassing stolen credentials.
    • IBM X-Force recorded a 44% increase in attacks beginning with exploitation of public-facing applications compared to the prior year.
    • Vulnerability exploitation was the leading cause of all attacks in IBM X-Force's dataset, accounting for 40% of incidents observed.
    • Microsoft Incident Response found 28% of breaches began through phishing or social engineering.
    • 18% of breaches in Microsoft's data started through unpatched web assets, and 12% through exposed remote services.
    • CrowdStrike observed a 42% year-over-year rise in zero-days exploited before public disclosure, compressing the window defenders have to patch before active exploitation begins.
    • Among China-nexus adversaries, 67% of exploited vulnerabilities granted immediate system access, and 40% targeted edge devices that typically lack comprehensive monitoring.
    • Incidents using fake CAPTCHA lures rose 563%, highlighting the shift to effective social engineering techniques.
    • Spam email volume rose 141%, compounding the volume of malicious messages reaching user inboxes.
    • ESET recorded ClickFix detections more than doubling between H2 2025 and H1 2026, as the technique expanded beyond browser error pages into AI-themed help screens and cloud authentication flows.
    • Once inside, the clock is short. CrowdStrike measured average eCrime breakout time at 29 minutes.
    • X-Force Red penetration tests found misconfigured access controls to be the most common entry point across engagements, which is a configuration problem rather than a detection one.
    • Microsoft accounted for 23% of all brand phishing attempts in April-June 2026, the most impersonated brand by a wide margin
    • The top five brands (Microsoft, LinkedIn, Google, Apple, Amazon) together account for more than half of all brand phishing attempts tracked in Q2 2026.
    • ChatGPT entered the top ten most impersonated brands for the first time in April-June 2026
    • Technology was the most targeted industry, followed by Social Networks and Banking

Strengthen your malware protection: Compare the best free antivirus software to detect threats and protect your devices without adding to your security budget.

How common is ransomware in 2026?

Ransomware now touches roughly half of every confirmed breach in the largest public dataset available. The encouraging part is that victims are refusing to pay in growing numbers and recovering from backups more often. The discouraging part is that encryption is succeeding more frequently than last year, and the operator pool is fragmenting into more groups that are harder to track.

48%

The share of all confirmed breaches that involved ransomware, up from 44% the previous year.

Source: Verizon

  • Payment refusal is now the norm. 69% of ransomware victims did not pay, making refusal the majority outcome in Verizon's dataset.
  • The median ransom actually paid fell to $139,875, down from $150,000 the previous year, continuing a multi-year decline.
  • Sophos found that 56% of ransomware attacks succeeded in encrypting data.
  • Malicious email is the leading root cause of ransomware at 26% in Sophos's survey, followed by phishing at 24%.
  • In 16% of ransomware attacks, data was both encrypted and stolen, combining ransom pressure with the threat of public exposure.
  • Exploited vulnerabilities fell to 18% as a ransomware entry point, down from 32% in the prior edition, a 14-point drop that reflects the shift toward social delivery.
  • Recovery is improving where preparation exists: backup-based recovery rose to 66% of attacks where data was encrypted, though only one in three smaller organizations stopped the attack before encryption at all.
  • IBM X-Force observed a 49% year-over-year increase in active ransomware and extortion groups, the steepest single-year rise in the tracked period.
  • Publicly disclosed victim counts rose only 12%, meaning more groups are each claiming fewer victims as the ecosystem fragments.
  • IBM's breach research found that 39% of breached organizations reported at least one ransomware incident, up from 34% the prior year.
  • Verizon recorded a 240% relative increase in threat actors leveraging legitimate remote monitoring and management software as part of ransomware operations.
  • Backdoor and command-and-control activity fell 27%, as attackers replaced custom malware with native administrative tools that blend into normal network traffic.
  • Microsoft independently found an RMM tool present in 79% of the ransomware cases it responded to.
  • Over 40% of ransomware attacks now have a hybrid component in Microsoft's data, spanning on-premises and cloud environments in a single incident.
  • ESET has documented over 100 EDR killers used in the wild, tools built specifically to disable security software mid-attack, with new variants appearing regularly.

What are infostealers and how much do they steal?

Infostealers are the quiet half of the malware economy. They do not encrypt anything or announce themselves. They harvest credentials, session cookies, and tokens, which are then sold to whoever wants access, which is why they so often turn up in the months before a ransomware attack becomes public. Their reach now extends to AI services alongside conventional enterprise accounts.

300,000+

ChatGPT credential sets exposed by infostealer malware in 2025, putting AI platforms on the same credential risk footing as core enterprise SaaS.

Source: IBM

  • Verizon found that 27% of ransomware victims had no associated infostealer or credential leak event in the year before being named as a victim.
  • 73% of ransomware victims did have an infostealer infection or credential leak event in the prior year, making credential theft the most common documented precursor to ransomware.
  • Collection is now the point of most intrusions. Data collection occurred in nearly 80% of Microsoft Incident Response engagements over the past year, feeding extortion and resale across criminal marketplaces.

How are supply chain attacks spreading malware?

The supply chain is the fastest-moving risk and the one least addressed by traditional endpoint controls, because the malicious code arrives through a channel the organization has already decided to trust. A compromised build pipeline, package registry, or SaaS integration delivers to every downstream customer at once, with a valid signature attached.

48%

The share of breaches now involving a third party, up 60% in a single year.

Source: Verizon

  • IBM X-Force identified a nearly fourfold increase in large supply chain and third-party compromises since 2020, the steepest multi-year growth of any breach category in its dataset.
  • The single largest financial theft ever reported came through this route. Elliptic attributes $1.46 billion in stolen cryptocurrency to PRESSURE CHOLLIMA, delivered via trojanized software in a supply chain compromise.
  • The WEF Global Cybersecurity Outlook 2026 found that 65% of large companies by revenue name third-party and supply chain vulnerabilities as their greatest cyber challenge, up from 54% in 2025.

Is AI changing how malware is built?

2026 is the first year with named samples rather than speculation. AI is accelerating steps attackers already performed rather than inventing new attack classes. What is genuinely new is malware that calls a language model while it runs, and AI systems becoming a target in their own right.

1 in 4

Malicious breaches that were AI-enabled, a 56% increase in a single year, and roughly $1 million more expensive than the global average breach.

Source: IBM

  • More than 20% of organizations reported a breach targeting their own AI models or applications.
  • Compromised APIs, applications, or plug-ins caused 27% of AI-targeted breaches, and cloud misconfigurations affecting AI workloads caused a further 27%.
  • The first AI-developed zero-day has been attributed. Google Threat Intelligence Group (GTIG) identified a threat actor using a zero-day exploit it believes was developed with AI, a two-factor authentication bypass in an open-source system administration tool, intended for a mass exploitation event that GTIG's counter-discovery may have prevented.
  • GTIG has confirmed four malware families using LLM-enabled obfuscation: PROMPTFLUX for dynamic self-modification, HONESTCUE for evasion payload generation, and CANFAIL and LONGSTREAM for AI-generated decoy logic.
  • LONGSTREAM contained 32 separate instances of code querying daylight saving status, inserted as inert AI-generated filler specifically to disguise the actual payload from analysis tools.
  • GTIG observed a repository packaging 85,000 real-world vulnerability cases as an AI code-skill plugin, designed to prime language models for vulnerability research and exploit generation.
  • APT45 sent thousands of repetitive prompts to recursively analyze CVEs and validate proof-of-concept exploits, using a language model as an automated research assistant to accelerate attack development.
  • CrowdStrike measured an 89% increase in attacks by AI-enabled adversaries compared to the prior year.
  • Legitimate GenAI tools were exploited at more than 90 organizations through injected prompts that generated credential-stealing and cryptocurrency-theft commands.
  • ChatGPT was mentioned in criminal forums 550% more than any other model, making it the dominant lure brand in the AI-enabled threat ecosystem.
  • ESET analyzed nearly 900,000 AI agent skills from public repositories and identified tens of thousands of suspicious instances.
  • Within that set, thousands of entries were outright malicious, carrying hidden code-execution routines embedded in components granted elevated system access.
  • Employee use of unapproved AI tools rose from 15% to 45% in a single year, making shadow AI the third most common non-malicious data leakage activity according to Verizon.
  • AI bot crawler traffic grew 21% month over month, against flat human traffic growth of 0.3%, a ratio that signals rapid automated scaling of AI-driven reconnaissance.
  • Microsoft recorded a 195% global rise in AI-driven forgeries. These techniques are now capable of defeating selfie checks and liveness tests by simulating natural eye blinks and head turns, enabling account takeover at the identity-verification layer.
  • The WEF Global Cybersecurity Outlook 2026 found that 94% of respondents identify AI as the most significant driver of change in cybersecurity in the year ahead.
  • 87% of respondents in the WEF Global Cybersecurity Outlook 2026 identified AI-related vulnerabilities as the fastest-growing cyber risk they observed in 2025, the highest consensus of any single risk category in the survey.
  • The share of organizations assessing the security of their own AI tools nearly doubled from 37% to 64% in a single year.
  • More than a third of organizations have no formal process to assess AI tool security, despite near-universal recognition of the risk.

How much does a malware attack cost?

Malware statistics show that most of the cost is a result of ransomware. It is the months spent finding the intrusion, escalating it, and absorbing the business that does not come back.

$4.99 million

The global average cost of a data breach, a record and a 12% year-over-year rise.

Source: IBM

  • Sophos found the median ransom demand fell to $698,000, continuing a multi-year decline from $1.3 million the prior year.
  • The median ransom payment fell to $769,000, down from $1 million the previous year, as more victims refused demands or negotiated reductions.
  • The average cost to recover from a ransomware attack, excluding any ransom paid, is $1,700,200 in the Sophos survey.
  • IBM found 41% of ransomware attacks exploited brand reputation as the primary pressure point, making reputational threat the most common coercion lever.
  • Employee data was the primary leverage in 35% of ransomware attacks, the second most common coercion target after brand reputation.
  • Intellectual property was the leverage in 31% of attacks, as attackers select whichever stolen asset creates the greatest payment pressure.
  • Organizations using AI and automation in security operations cut breach costs by an average of almost $2 million, yet one in four have still not adopted these tools in their security operations.
  • The spending trigger is shifting from experience to anticipation. 85% of organizations said they planned to increase security spending after learning about advanced frontier AI cyber capabilities.
  • Only 64% said they plan to increase spend on security after actually experiencing a breach, meaning awareness of AI threats is a stronger spending trigger than lived incident experience.

Which industries and regions are hit hardest by malware?

Manufacturing has been the most attacked sector for five consecutive years, and North America has just become the most attacked region for the first time since 2019. Both facts point the same way: attackers concentrate where operational downtime is expensive and where data has resale value.

27.7%

Manufacturing's share of all incidents observed by IBM X-Force in 2025, keeping it at the top of the target list for a fifth consecutive year.

Source: IBM

  • Data theft was the most common impact within manufacturing, rather than the production shutdown usually associated with the sector.
  • North America accounted for 29% of all incidents observed by IBM X-Force, the highest share of any region and the first time in six years it has ranked as the most attacked region, up from 24% the prior year.
  • Data encryption in healthcare attacks fell to 34% in 2025, down from 74% in 2024, as the proportion of attacks stopped before encryption reached a five-year high.
  • Extortion-only attacks against healthcare organizations, where data was not encrypted but a ransom was still demanded, tripled to 12% of attacks in 2025, the highest rate of any sector in the survey.
  • IBM found 62% of AI-driven attacks targeted critical infrastructure sectors.
  • Financial services breaches averaged $6.3 million per incident when AI-driven attacks were involved, 26% above the $4.99 million global average.
  • Energy sector breaches averaged $5.2 million per incident, also above the global average and consistent with critical infrastructure attracting premium targeting.
  • CrowdStrike recorded a 38% increase in China-nexus intrusions across all sectors compared to the prior year.
  • Logistics saw an 85% increase in China-nexus targeting specifically, reflecting a strategic priority on disrupting trade and supply chain visibility.
  • North Korea-nexus incidents rose 130% as financially motivated operations scaled up, particularly in cryptocurrency theft and financial sector intrusions.
  • Destructive campaigns against cloud environments rose 87% in Microsoft's data, a category where recovery depends on architecture rather than on endpoint tooling.
  • The WEF Global Cybersecurity Outlook 2026 found 64% of organizations are now explicitly accounting for geopolitically motivated cyberattacks in their risk mitigation strategies.
  • 91% of the largest organizations have changed their cybersecurity strategy as a direct result of geopolitical volatility.
  • 31% of WEF survey respondents reported low confidence in their nation's ability to respond to a major cyber incident, up from 26% the prior year.
  • 84% of Middle East and North Africa respondents are confident in their country's ability to protect critical infrastructure, among the highest of any region surveyed.
  • Only 13% of Latin America and Caribbean respondents share that confidence, the lowest of any region in the WEF survey.

What do mobile malware statistics show about smartphone threats?

Mobile malware volumes fell in 2026 compared to their 2025 peak, but the composition has shifted toward higher-value targets. Banking trojans now dominate, preinstalled backdoors are appearing more frequently on new devices, and attackers are building smarter evasion into the malware itself.

2,676,328

Mobile malware, adware, and unwanted software attacks blocked by Kaspersky in January to March 2026, down from 3,239,244 in the prior three months.

Source: Securelist by Kaspersky

  • A total of 1,996,823 mobile attacks were blocked in April to June 2026. Of 304,128 malicious installation packages detected, 93,574 were mobile banking trojans, and 570 were mobile ransomware trojans.
  • Trojan-Banker was the most prevalent mobile malware category in April to June 2026, accounting for 30.77% of all detected application packages.
  • Trojan-Banker was also the most prevalent category in January to March 2026, at 52.96% of all detected application packages. The drop between periods reflects reclassification of some banking trojans into the dropper category, not a fall in attacker activity.
  • Verizon found mobile-centric social engineering, specifically fake text messages and voice calls, succeeds at a rate 40% higher than traditional email phishing.

How do buyers rate malware analysis tools on G2?

The malware statistics in this section are drawn from four consecutive Fall editions of the G2 Grid Report for Malware Analysis Tools: Fall 2023, Fall 2024, Fall 2025,  and Fall 2026. G2 Data represents verified reviews from people who actually use the software, aggregated across every product that qualified for the report.

67

The Net Promoter Score (NPS) in 2026, up from 60 in 2023 and the highest in the four-year series.

Source: G2 Grid Report for Malware Analysis Tools

G2 Grid Report for Malware Analysis Tools, Fall 2023 to Fall 2026, satisfaction ratings

Grid Report edition Likelihood to recommend Net Promoter Score Meets requirements Product going in the right direction
Fall 2023 89% 60 91% 84%
Fall 2024 89% 62 91% 86%
Fall 2025 90% 66 91% 91%
Fall 2026 90% 67 91% 91%
  • NPS rose from 60 to 67 across four consecutive Fall editions, the highest in the series and consistent with a category where detection accuracy is a given and evaluation now centers on analyst workflow and vendor relationship.
  • Meets requirements has held at 91% across all four editions without moving a single point, the most stable metric in the category. The tools reliably do what they promise; the harder question is what to point them at.
  • Product going in right direction climbed seven points, from 84% to 91%, the largest gain of any satisfaction metric in the four-year period.

What's next for malware in 2026 and beyond?

Attackers have automated the discovery and weaponization of vulnerabilities; defenders have automated almost everything except the remediation of them. That asymmetry is where the next two years of incidents will come from.

18%

The share of organizations applying AI agents to vulnerability management, against more than 50% using them for threat detection and containment

Source: IBM

  • The exploitation window is closing faster than patch cycles can move. Verizon reports AI is compressing the time from a known vulnerability to active exploitation from months to hours, which makes the 18% automation figure above a compounding exposure rather than a static one.
  • Three quarters of organizations say frontier AI threats are prompting them to rethink how agents are deployed across their security operations.
  • Only 37% of breached organizations encrypt sensitive data both at rest and in transit.
  • Just 34% of breached organizations have full visibility into their cryptographic assets, a gap that will become critical as quantum computing capabilities mature.
  • Awareness of frontier capability is now widespread: 78% of organizations in IBM's follow-on study, 356 of 456 respondents, were aware of recent reporting on highly advanced frontier models.

What do these malware statistics mean for you?

The through-line across every dataset I read is that detection accuracy is no longer the binding constraint. What is failing is the middle: triage capacity, investigation speed, and the ability to connect a credential-theft event to the ransomware deployment that follows it months later.

For most teams, the honest next step is not another detection layer. It is closing the automation gap on remediation, tightening the configuration and patching discipline that now accounts for the largest share of entry points, and treating credential theft as the leading indicator it has turned out to be.

What happens when cyberthreats succeed? Explore the 22 biggest cyberattacks in history that made global headlines and reshaped cybersecurity.

*This article was originally published in 2024. It has been updated in 2026 with new information.