[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fr9_Rd-etJVCagPfQxLvrKURNnl42KiTZw2lTs5zvmj0":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"96aec355-c99f-4e18-a57f-4a18b19e5274","IT threat evolution in Q2 2026. Non-mobile statistics","it-threat-evolution-in-q2-2026-non-mobile-statistics-3d6c6e","The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.","Kaspersky's Q2 2026 threat report highlights a surge in ransomware attacks, with Qilin being a prominent family. Microsoft disrupted a malware-signing service used by multiple ransomware groups, including Rhysida and Akira. The report also details active exploitation of Windows vulnerability CVE-2026-33825 and a zero-day in Check Point VPNs (CVE-2026-50751) exploited by the Qilin group.","Kaspersky report details Q2 2026 IT threat evolution, including ransomware, miners, and macOS\u002FIoT attacks.","Table of Contents Quarterly figuresRansomwareQuarterly trends and highlightsThreat actor disruptionVulnerabilities and attacksThe most prolific groupsNumber of new ransomware variantsNumber of users attacked by ransomware TrojansTOP 10 countries and territories attacked by ransomware TrojansTOP 10 most common families of ransomware TrojansMinersNumber of new miner variantsNumber of users attacked by minersTOP 10 countries and territories attacked by minersAttacks on macOSQuarterly highlightsTOP 20 threats to macOSTOP 10 countries and territories by share of attacked usersIoT threat statisticsTOP 10 threats delivered to IoT devicesAttacks on IoT honeypotsAttacks via web resourcesTOP 10 countries and territories that served as sources of web-based attacksCountries and territories where users faced the greatest risk of online infectionLocal threatsCountries and territories where users faced the highest risk of local infection Authors AMR IT threat evolution in Q2 2026. Non-mobile statistics IT threat evolution in Q2 2026. Mobile statistics The statistics in this report are based on detection verdicts returned by Kaspersky products unless otherwise stated. The information was provided by Kaspersky users who consented to sharing statistical data. Quarterly figures In Q2 2026: Kaspersky products blocked nearly 400 million attacks that originated with various online resources. Web Anti-Virus responded to 52 million unique links. File Anti-Virus blocked more than 16 million malicious and potentially unwanted objects. There were 2538 new ransomware variants discovered. More than 71,000 users experienced ransomware attacks. 15% of all ransomware victims whose data was published on threat actors’ data leak sites (DLS) were attacked by Qilin. More than 213,000 users were targeted by miners. Ransomware Quarterly trends and highlights Threat actor disruption Microsoft has dismantled an illicit malware-signing service used by ransomware operators. Microsoft’s Digital Crimes Unit has shut down a malware-signing-as-a-service (MSaaS) operation run by the threat group Fox Tempest. The illicit service abused the Microsoft Artifact Signing platform to generate digital signature certificates for malicious software. Malware signed by these certificates was observed in campaigns conducted by such ransomware groups as Rhysida, Akira, INC, Qilin, and BlackByte. The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers. To disrupt the operation, Microsoft seized the domain used by the MSaaS platform, revoked all associated certificates, and disabled the related accounts. Additionally, the company filed a lawsuit against Fox Tempest. Vulnerabilities and attacks CISA has confirmed that a Windows vulnerability known as BlueHammer is actively being exploited in ransomware attacks. On April 22, the agency updated its Known Exploited Vulnerabilities (KEV) catalog to note the ongoing ransomware exploitation of CVE-2026-33825. The local privilege escalation flaw in Microsoft Defender was originally disclosed earlier in April. Although Microsoft released a fix on April 14, unpatched systems remain vulnerable. CISA did not disclose further details or attribute the attacks to specific threat groups. Check Point has linked zero-day exploitation of CVE-2026-50751 to the Qilin ransomware group. The critical vulnerability affects Check Point Remote Access VPN and Mobile Access. Attackers began exploiting the flaw as a zero-day on May 7, with activity spiking sharply in early June. While several dozen organizations have been targeted, at least one incident has been definitively tied to Qilin. Check Point also disclosed a related certificate validation flaw (CVE-2026-50752) that affects site-to-site VPN connections relying on the legacy IKEv1 key exchange protocol. Researchers assess with high confidence that the PayoutsKing group is leveraging the legitimate QEMU emulator to deploy hidden, Alpine Linux-based virtual machines on compromised hosts. Because security solutions often lack visibility inside virtualized environments, the threat actors use this technique to evade detection. Inside the VM image, the operators deploy various tools — such as credential theft software — and configure the virtual machine as a backdoor managed via a reverse SSH tunnel to their command-and-control infrastructure. While the technique is not new, and we’ve detailed it before, it remains relatively rare in ransomware attacks. The most prolific groups This section highlights the most prolific ransomware gangs by number of victims added to each group’s DLS. Qilin reclaimed the top spot (accounting for 14.57% of total listings) after placing second last quarter. It is followed by the Akira ransomware (7.80%) and the DragonForce RaaS group (6.88%). Number of each group’s victims according to its DLS as a percentage of all groups’ victims published on all the DLSs under review during the reporting period (download) Number of new ransomware variants In Q2, Kaspersky solutions detected four new ransomware families and 2538 new modifications. This signals a continued stabilization following spikes seen in Q1 and Q4 of last year. Number of new ransomware modifications, Q2 2025 — Q2 2026 (download) Number of users attacked by ransomware Trojans Our solutions protected a total of 71,860 unique users from ransomware during Q2. Ransomware activity peaked in April, with 31,206 targeted users recorded during that month. Number of unique users attacked by ransomware Trojans, Q2 2026 (download) TOP 10 countries and territories attacked by ransomware Trojans Country\u002Fterritory* %** 1 South Korea 0.87 2 Pakistan 0.76 3 China 0.71 4 Libya 0.49 5 Tajikistan 0.46 6 Turkmenistan 0.38 7 Cameroon 0.38 8 Indonesia 0.36 9 Bangladesh 0.36 10 Mozambique 0.34 * Excluded are countries and territories with relatively few (under 50,000) Kaspersky users. ** Unique users whose computers were attacked by ransomware Trojans as a percentage of all unique users of Kaspersky products in the country\u002Fterritory. TOP 10 most common families of ransomware Trojans Name Verdict %* 1 (generic verdict) Trojan-Ransom.Win32.Gen 28.02 2 WannaCry Trojan-Ransom.Win32.Wanna 7.14 3 (generic verdict) Trojan-Ransom.Win32.Crypren 6.27 4 (generic verdict) Trojan-Ransom.Win32.Agent 4.89 5 (generic verdict) Trojan-Ransom.Win32.Encoder 4.65 6 (generic verdict) Trojan-Ransom.Python.Agent 3.07 7 (generic verdict) Trojan-Ransom.Win32.Crypmod 2.70 8 (generic verdict) Trojan-Ransom.MSIL.Agent 2.45 9 PolyRansom\u002FVirLock Virus.Win32.PolyRansom \u002F Trojan-Ransom.Win32.PolyRansom 2.31 10 (generic verdict) Trojan-Ransom.Win32.Phny 2.12 * Unique Kaspersky users attacked by the specific ransomware Trojan family as a percentage of all unique users attacked by this type of threat. Miners Number of new miner variants In Q2 2026, Kaspersky solutions detected 6067 new miner variants, almost twice the number for the previous reporting period. Number of new miner modifications, Q2 2026 (download) Number of users attacked by miners In Q2, we detected attacks using miner programs on the computers of 213,003 unique Kaspersky users worldwide. Number of unique users attacked by miners, Q2 2026 (download) TOP 10 countries and territories attacked by miners Country\u002Fterritory* %** 1 Mali 1.56 2 Senegal 1.54 3 Tanzania 1.32 4 Panama 1.04 5 Bangladesh 1.03 6 Ethiopia 0.87 7 Costa Rica 0.67 8 Bolivia 0.67 9 Côte d’Ivoire 0.65 10 Kazakhstan 0.62 * Excluded are countries and territories with relatively few (under 50,000) Kaspersky users. ** Unique users whose computers were attacked by miners as a percentage of all unique users of Kaspersky products in the country\u002Fterritory. Attacks on macOS Quarterly highlights In April, Aikido researchers reported a new attack by the GlassWorm stealer, which was distributed via malicious IDE extensions on the Open VSX Registry. The payload operated by installing a secondary malicious extension across all installed IDE e","https:\u002F\u002Fsecurelist.com\u002Fmalware-report-q2-2026-pc-iot-statistics\u002F120960\u002F","https:\u002F\u002Fmedia.kasperskycontenthub.com\u002Fwp-content\u002Fuploads\u002Fsites\u002F43\u002F2026\u002F08\u002F10093530\u002Fmalware-report-q2-2026-featured-image-scaled-1.jpg","2026-08-10T10:00:37+00:00","2026-08-10T12:00:15.242057+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"Kaspersky","vendor",{"name":22,"type":23},"Fox Tempest","threat_actor",{"name":25,"type":23},"Rhysida",{"name":27,"type":23},"Akira",{"name":29,"type":23},"INC",{"name":31,"type":23},"Qilin","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":32,"icon":34,"name":35,"slug":36},null,"Malware","malware",[38,43,48,50],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"7d8b5ab8-ea0b-4ced-ae97-ec251b86993a","Ransomware","ransomware",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":49},{"id":32,"icon":34,"name":35,"slug":36},{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[56,60,63],{"type":57,"value":58,"context":59},"cve","CVE-2026-33825","Windows vulnerability known as BlueHammer, actively exploited in ransomware attacks.",{"type":57,"value":61,"context":62},"CVE-2026-50751","Zero-day vulnerability affecting Check Point Remote Access VPN and Mobile Access, exploited by Qilin ransomware.",{"type":57,"value":64,"context":65},"CVE-2026-50752","Certificate validation flaw affecting site-to-site VPN connections using IKEv1."]