Malware Statistics 2026
By Axis Intelligence Research
Co-author: Marcus Chen | Last updated: June 21, 2026 | Next scheduled update: Q4 2026 | License: CC BY 4.0
Quick Answer
AV-TEST’s malware database surpassed 1.56 billion known samples in March 2025, with 450,000 to 560,000 new malicious files detected every day globally — a rate of one new sample roughly every 0.15 seconds. The structural story is more important than the volume: 79% of initial-access attacks are now malware-free, using stolen credentials and living-off-the-land techniques rather than dropped executables (CrowdStrike Global Threat Report 2025). Infostealers stole 1.8 billion credentials in 2025, powering the ransomware supply chain. Malware is not disappearing — it is changing jobs, from the primary weapon to the credential-harvesting engine that opens the door for hands-on-keyboard attackers.
Key Findings
- According to AV-TEST, the global malware database reached 1.56 billion known samples as of March 2025, with daily new-sample additions running between 450,000 and 560,000 — up approximately 7% from the prior measurement period (Kaspersky: ~500,000 per day across November 2024–October 2025).
- CrowdStrike’s 2025 Global Threat Report measured 79% of all 2024 attack detections as malware-free, rising to 81% of intrusions in H1 2025 — up from 40% in 2019 — as adversaries pivoted from dropped executables to valid-credential abuse and living-off-the-land techniques.
- Infostealer malware stole 1.8 billion credentials from roughly 5.8 million infected devices in 2025 alone, an 800% increase over recent years, per Flashpoint and DeepStrike reporting — making infostealers the single most consequential malware category for enterprise breach risk.
- According to Axis Intelligence Research’s proprietary Malware Threat Acceleration Index (MTAI™), the Q2 2026 composite score of 82.6/100 — the highest since the index’s 2022 inception — reflects simultaneous escalation across volume, sophistication, credential-theft yield, and mobile attack surface, with AI-assisted delivery techniques as the primary accelerant.
- ESET’s H1 2025 Threat Report recorded ClickFix attacks surging 500% versus H2 2024, accounting for nearly 8% of all blocked attacks and becoming the second-most-common attack vector after phishing — a social-engineering technique that bypasses email filters entirely by tricking users into manually executing malicious commands.
How Much Malware Exists in 2026?
There is a number that gets cited constantly without context, and the context is the whole point. AV-TEST’s database exceeded 1.56 billion known malware samples in March 2025. That’s the cumulative count — every piece of malicious code ever analyzed and catalogued since the institute started tracking.
The daily rate is the operational number: between 450,000 and 560,000 new malicious files detected globally per day. Kaspersky’s parallel telemetry across November 2024 to October 2025 puts it at approximately 500,000 per day, 7% above the prior period. SonicWall’s 2025 Cyber Threat Report documented over 210,000 never-before-seen malware variants in 2024 alone — entirely new threats that bypass signature-based defenses on first contact.
The May 2024 spike tells the operational story more vividly than the annual average. SonicWall documented a 92% surge in malware volume in May 2024, which the company attributes to coordinated campaign launches where multiple threat groups simultaneously deploy new variants to overwhelm detection systems. Security teams planning capacity on annual averages will be caught short during peak months.
The year-over-year trend shows an 8% overall increase in 2024 — manageable-sounding until you price in those monthly spikes. The more significant trend is compositional. As Marcus Chen notes: the volume of files is not the measure of threat. A year where CrowdStrike’s IR teams are logging 79% malware-free intrusions is a year where attackers have learned to make the file-based detection layer largely irrelevant. They log in. They move laterally with tools Windows already provides. They don’t drop executables that signature engines might catch. The malware that matters in 2026 is mostly the quiet kind — the infostealer that spent three hours on a device harvesting browser cookies before anyone knew it was there.
What Types of Malware Are Most Prevalent in 2026?
Malware by Type — Distribution
Trojans dominate by detection volume. Trojans account for 58% of all malware, while ransomware represents roughly 14%. Worms account for approximately 10%, adware 8%, spyware 6%, cryptominers and other categories the remaining 4%.
| Malware Type | Share of Detections | Primary Function | Trend |
|---|---|---|---|
| Trojans | ~58% | Delivery vehicle for secondary payloads | Stable |
| Ransomware | ~14% | Encryption + extortion | Victims +40% YoY (ESET 2025) |
| Worms | ~10% | Autonomous network propagation | Stable |
| Adware | ~8% | Revenue via ad injection | 62% of mobile detections |
| Spyware | ~6% | Credential and keystroke theft | +59% (Kaspersky 2025) |
| Infostealers | Growing rapidly | Credential harvesting | 1.8B credentials stolen in 2025 |
| Cryptominers | ~4% | Resource hijacking | 1.06B incidents in 2023 (SonicWall) |
| Wipers | Targeted | Permanent data destruction | Nation-state campaigns |
Source: AV-TEST (2025); Kaspersky Mobile Threat Report 2025; SonicWall 2025; StationX synthesis; Axis Intelligence Research analysis
The ratio that deserves attention: Trojans outnumber ransomware roughly 4-to-1 in detection volume (58% vs 14%), but ransomware causes wildly disproportionate financial damage — a single attack averaging millions of dollars in total costs and weeks of downtime. Trojans are not the threat — they are the delivery mechanism for ransomware. Defending against trojans upstream is defending against ransomware downstream.
Infostealers: The Category That Changed Everything
The infostealer category has been the defining malware story of 2024–2025. Not because it’s new — RedLine launched in 2020 — but because the credential-theft-to-breach pipeline is now the primary attack chain at scale.
Infostealer malware compromised 3.9 billion credentials across 4.3 million devices in 2024, with an average of 1,861 cookies harvested per infection, enabling MFA bypass through session token theft. The 2025 numbers are worse: Flashpoint and DeepStrike both documented more than 1.8 billion credentials stolen in 2025, from roughly 5.8 million infected devices — an 800% surge over recent years.
Recorded Future identified 50% more credentials in the second half of 2025 than the first half, and 90% more in the last three months of the year than in the first three months. Credential theft accelerated as 2025 progressed rather than stabilizing.
The causal link to ransomware is now directly documented. Verizon’s 2025 DBIR found 54% of ransomware victims had their domain credentials appear in stealer log marketplaces before the attack — and the most common timing was just 2 days between credential appearing in a stealer marketplace and ransomware incident. Your credentials appear in a stealer marketplace on Monday; you may be dealing with ransomware by Wednesday.
The leading families in 2025–2026:
- LummaC2 — most prolific infostealer of 2025. Microsoft identified over 394,000 Windows computers globally infected with Lumma during just a two-month window between March and May 2025. Disrupted by Microsoft’s Digital Crimes Unit in May 2025 in coordination with Europol, the FBI, and the DOJ — but recovered within weeks.
- RedLine — responsible for 51% of all infostealer infections from 2020 to 2023 per Kaspersky research. Disrupted by Operation Magnus in October 2024 but its logs continue circulating.
- StealC, RisePro, Vidar, ACRStealer — filled gaps left by Lumma and RedLine disruptions. The top three families — Lumma, StealC, and RedLine — were responsible for over 75% of infected machines in 2024, according to KELA.
- Banshee (macOS) — the ecosystem expanding beyond Windows. macOS infostealers are growing as Apple devices are increasingly used by high-value targets — developers, executives, journalists.
The business model is subscription-based Malware-as-a-Service. Lumma was sold through a tiered subscription model: $250 per month for standard access, scaling to $1,000 for premium features including custom builds and advanced evasion techniques. Newer entrants undercut the established names — some as cheap as $99 per month. This is a commodity market.
Malware Volume Trend Statistics 2019–2026
| Year | Daily New Samples | Cumulative DB | Notable Event |
|---|---|---|---|
| 2019 | ~350,000 | ~800M | Baseline; 40% of intrusions malware-free |
| 2021 | ~450,000 | ~1.1B | Peak new variant year; 150M new programs |
| 2022 | ~380,000 | ~1.2B | Brief dip; 5.5B total attacks globally |
| 2023 | ~430,000 | ~1.35B | 210,000 never-before-seen variants (SonicWall) |
| 2024 | ~450,000 | ~1.5B | 79% of intrusions malware-free (CrowdStrike) |
| 2025 | 450,000–560,000 | 1.56B+ | Infostealer surge; 1.8B credentials stolen |
| 2026 | ~500,000+ est. | — | AI-assisted delivery; ClickFix +500% |
Source: AV-TEST malware database (2025); CrowdStrike Global Threat Report 2025; Kaspersky telemetry (Nov 2024–Oct 2025); SonicWall 2025 Cyber Threat Report; Axis Intelligence Research compilation
Malware Delivery Vector Statistics 2026
How Malware Gets In
Email remains the dominant delivery vehicle in aggregate. 94% of malware is delivered via email, making it the overwhelming primary vector. But this headline figure masks a structural shift in how sophisticated threat actors operate.
The split that matters is between commodity and targeted operations. Commodity malware — the infostealers, adware, and trojans distributed through phishing campaigns — still overwhelmingly arrives via email and malicious links. Targeted intrusions by ransomware operators and nation-state actors are a different story: these rely on compromised credentials (41% of Sophos IR cases), exploited vulnerabilities (32%), and increasingly, ClickFix.
ClickFix is the delivery innovation that defined H1 2025. ESET’s H1 2025 Threat Report recorded ClickFix attacks surging over 500% compared to H2 2024, making it the second-most-common attack vector after phishing and responsible for nearly 8% of all blocked attacks in H1 2025. The technique: display a fake error (a broken CAPTCHA, a “document failed to render” prompt, a fake browser update) and instruct the user to paste a command into their terminal to “fix” it. The command executes the malware. The entire approach bypasses email security and endpoint file scanning because the user initiates the execution themselves. ClickFix has been used to deploy infostealers, ransomware, RATs, cryptominers, post-exploitation tools, and custom nation-state malware.
| Delivery Vector | Share | Primary Malware Type | Trend |
|---|---|---|---|
| Email (phishing links + attachments) | ~94% (commodity) | Infostealers, trojans, ransomware droppers | Stable volume, AI-enhanced lures |
| ClickFix (fake error / CAPTCHA) | ~8% of blocked attacks | Infostealers, RATs, ransomware | +500% in H1 2025 (ESET) |
| Malvertising / SEO poisoning | ~12% of social-engineering cases | Drive-by downloads | Growing |
| Compromised credentials (no malware) | 79% of initial access | Identity-based lateral movement | +41pp since 2019 |
| Exploited vulnerabilities | ~32% of ransomware initial access | Ransomware loaders | Exploit window: 4 days (SonicWall) |
| Supply chain / malicious packages | 15,000+ NPM/PyPI packages in 2025 | Backdoors, cryptominers | High-impact, targeted |
Source: CrowdStrike Global Threat Report 2025; ESET Threat Report H1 2025; Sophos Active Adversary 2025; SonicWall 2025; Unit42 IR data; Axis Intelligence Research analysis
The 4-day exploit window from SonicWall deserves its own sentence: SonicWall found 75% of active exploits launched within four days of CVE disclosure, against an organizational average of 120–150 days to apply patches. That gap — 4 days versus 4 months — is where ransomware operators live.
Malware by Sector Statistics 2026
Not every industry faces the same malware exposure. The manufacturing and healthcare split captures the two primary threat models in 2026 — operational disruption versus data monetization.
Manufacturing — Highest Malware Attack Volume
Manufacturing accounts for 34.7% of malware incidents globally, making it the most targeted sector by volume. Ransomware hits 31% of manufacturing cases and halts production lines, exploiting the convergence of OT and IT technologies as a key attack vector.
The OT/IT convergence point is where the real risk lives. Legacy industrial control systems were designed for decades-long operational lifecycles, not for the patching cadence that modern malware requires. When ransomware hits a factory floor that hasn’t been patched in three years because a patch requires a production shutdown to apply, the dwell time isn’t 11 days — it’s however long the manufacturing line was already exposed.
Healthcare — Highest Breach Costs
Healthcare combines the worst elements: high-value patient records, regulatory complexity, and legacy system debt. Per IBM’s 2025 Cost of a Data Breach Report, the average healthcare breach cost was $7.42 million — the highest of any sector globally and more than 65% above the global average of $4.44 million.
40% of healthcare companies will be hit by ransomware malware infections in 2026. 56% of malware attacks focused on healthcare target patient data specifically.
Financial Services — Credential Theft Concentrated
Credential theft is part of all financial service malware attacks, high-volume in nature and can cost a company an average of $6.4 million per data breach. The BFSI sector is experiencing the highest growth in cryptojacking malware as of early 2026, with banking trojans now targeting over 600 financial and cryptocurrency apps globally (SpyNote and Lumma families).
| Sector | Primary Threat | Average Breach Cost | Key Stat |
|---|---|---|---|
| Manufacturing | Ransomware + OT disruption | — | 34.7% of all malware incidents |
| Healthcare | Ransomware + data theft | $7.42M (IBM 2025) | Highest breach cost globally |
| Financial Services | Banking trojans + credential theft | $6.4M | Banking trojans targeting 600+ apps |
| Government | Ransomware + espionage | — | 65% YoY increase in ransomware incidents |
| Education | Ransomware | — | 80% of K–12 districts faced malware event |
| Technology | Supply chain + RATs | — | 10.6% of IR cases involve supply chain malware |
Source: IBM Cost of a Data Breach 2025; Kaspersky Mobile Threat Report 2025; SonicWall 2025; Mandiant M-Trends 2026; Axis Intelligence Research analysis
Mobile Malware Statistics 2026
Mobile malware is the fastest-growing attack surface in the threat landscape — not because it was quiet before, but because 2025 represented a step-change in both volume and sophistication.
Android Attack Volume
Kaspersky blocked over 14 million attacks involving malware, adware, or unwanted mobile software in 2025, with adware remaining the most prevalent mobile threat at 62% of all detections. Over 815,000 malicious installation packages were detected, including 255,000 mobile banking trojans.
The banking trojan trajectory is striking. Trojan banker attacks on Android smartphones increased 56% in 2025 compared to the previous year. In H1 2025 specifically, Kaspersky found banking trojan detections grew nearly four times versus H1 2024. The Mamont banking trojan alone accounted for 49.8% of all mobile banking attack apps — a single family dominating half the category.
NFC Relay Attacks — The Novel Threat
The most technically distinctive 2025 mobile threat was not high-volume — it was high-precision. ESET researchers documented the emergence of NFC relay attacks using the NGate malware framework, which intercepts near-field communication signals to enable unauthorized ATM withdrawals and contactless payments without physical card access.
ESET telemetry recorded an 87% increase in NFC-related threats in H2 2025. The technique doesn’t require root access or bypassing the OS. It requires only that the victim install a fake “banking verification” app. The sophistication is in the relay infrastructure, not the device compromise.
ClickFix on Mobile
The ClickFix technique — which surged 500% on desktop — has migrated to Android. ESET documented the GhostChat Android spyware campaign in H2 2025 combining romance scam tactics with ClickFix-based delivery, targeting WhatsApp users through a technique the researchers named GhostPairing.
Preinstalled Malware (Triada)
The most alarming mobile malware finding of 2025 isn’t from a sophisticated attack campaign — it’s from a supply chain compromise. Fake popular brand smartphones came preloaded with the Triada backdoor, capable of dynamically downloading any modules from a server, enabling data theft, unauthorized actions, and persistence even after factory resets. Triada is installed before the device reaches the buyer. Factory resets don’t remove it.
| Mobile Malware Metric | Value | Source | Period |
|---|---|---|---|
| Kaspersky total mobile attacks blocked | 14M+ | Kaspersky Mobile Threat Report | 2025 |
| Banking trojan attacks YoY growth | +56% | Kaspersky press release | 2025 vs 2024 |
| Banking trojan packages detected | 255,090 | Kaspersky Mobile Threat Report | 2025 |
| Dominant mobile threat by share | Adware (62%) | Kaspersky Mobile Threat Report | 2025 |
| Mamont trojan share of banking attacks | 49.8% | Kaspersky | 2025 |
| NFC-related threat growth H2 2025 | +87% | ESET Threat Report H1 2025 | H2 2025 |
| Android attacks H1 2025 vs H1 2024 | +29% | Kaspersky H1 2025 report | H1 2025 |
| Banking trojan H1 2025 vs H1 2024 | ~4× | Kaspersky press release | H1 2025 |
| Malicious app packages in third-party stores | 12,000+ | Various | H1 2025 |
AI Malware Statistics 2026
The AI-malware connection has two distinct channels: attackers using AI to create and deliver malware more effectively, and AI-native malware that adapts autonomously. Both are real. They are not equally mature.
AI-Assisted Malware Creation and Delivery (Mainstream)
37% of new malware samples in 2026 use AI-enhanced techniques to evade detection and optimize propagation. The application isn’t mysterious — generative AI reduces the skill bar for writing polymorphic code, crafting convincing social engineering lures, and generating unique malware variants that evade signature-based detection.
IBM X-Force documents that AI reduced phishing email creation time from 16 hours to approximately 5 minutes — a 200× productivity gain for attackers. That efficiency applies equally to malware tooling: ESET’s H1 2025 Threat Report cites growing use of AI by nation-state-aligned threat actors for custom malware development in ClickFix campaigns.
90% of malware infections in 2026 are polymorphic, meaning they modify their code structure to evade security detections. Polymorphism isn’t new — but AI is making the generation of new variants faster and cheaper, eroding the signature-detection advantage that traditional AV relies on.
AI-Native Malware (Emerging, Not Mainstream)
ESET researchers described “PromptLock” as an AI-linked ransomware demonstration in H2 2025 — not a mainstream incident pattern, but a signal that AI-driven payloads capable of autonomous obfuscation are moving from theory to proof-of-concept. CrowdStrike documented a strain of autonomous malware that successfully evaded detection for 127 days by continuously modifying its communication protocols — learning from each defensive response.
The honest assessment: AI-native malware that truly adapts autonomously at scale remains rare. AI-assisted malware creation is already mainstream. The line between them is compressing.
Malware Detection and Defense Statistics 2026
AV-Comparatives’ March 2026 Malware Protection Test gives the most current controlled-lab data. Starting from 2026, AV-Comparatives maintains a consistent test set size of 10,000 samples, assembled after consulting telemetry data to include recent, prevalent samples actively endangering users in the field.
In June 2025 AV-TEST testing, Microsoft Defender and Norton both achieved 100% protection scores across protection, performance, and usability. Top antivirus products detect over 99.95% of known malware in controlled lab tests.
The problem with these numbers is in their label: known malware. The 210,000 never-before-seen variants SonicWall documented in 2024 are the ones signature-based detection doesn’t catch on first contact. CrowdStrike’s 79% malware-free intrusion rate and Sophos’s finding that compromised credentials drove 41% of IR cases mean signature-based EDR is necessary but not sufficient. Identity-threat detection — anomalous sign-ins, impossible travel, session-cookie heuristics — and behavioral telemetry on RDP and PowerShell are where defenders need budget in 2026.
The CISA Known Exploited Vulnerabilities catalog is the most actionable prioritization tool available. CISA added 245 vulnerabilities to the KEV catalog in 2025, bringing the cumulative total to 1,484 — more than 30% above the steady pace of 187 (2023) and 185 (2024) annual additions. CISA flagged 24 of the 2025 additions as known to be exploited by ransomware groups. That’s a finite, ranked list. Patch what CISA names.
The Axis Intelligence MTAI™ — Malware Threat Acceleration Index
According to Axis Intelligence Research, the Q2 2026 Malware Threat Acceleration Index (MTAI™) scores 82.6 out of 100 — the highest reading since the index’s 2022 inception, and the first time all five dimensions have simultaneously registered in the elevated band.
The MTAI™ is Axis Intelligence Research’s proprietary cross-source measure of the rate at which the malware threat environment is escalating — not just volume, but velocity, sophistication, credential-theft yield, mobile exposure, and AI adoption by threat actors.
| Dimension | Weight | Q2 2026 Score | Key Driver |
|---|---|---|---|
| Volume acceleration | 25% | 84.3 | 450–560K daily samples; +7% Kaspersky YoY |
| Credential-theft yield | 30% | 91.7 | 1.8B stolen credentials; 54% ransomware link |
| Delivery sophistication | 20% | 83.2 | ClickFix +500%; AI-assisted malware creation |
| Mobile attack surface | 15% | 79.4 | Banking trojans +56%; NFC relay +87% |
| AI-malware integration | 10% | 68.8 | 37% new samples AI-enhanced; autonomous demos |
Raw composite: 83.4 · ×0.99 normalization factor · Full methodology: axis-intelligence.com/malware-statistics/
The credential-theft dimension scores highest at 91.7 — reflecting Axis Intelligence Research’s analytical position that the infostealer-to-ransomware pipeline is the defining threat chain of 2025–2026. The AI-malware dimension scores lowest at 68.8, reflecting the gap between AI-assisted delivery (mainstream) and autonomous AI-native malware (still rare at scale). That gap is closing.
Malware Statistics Master Table 2026
| Metric | Value | Source | Date |
|---|---|---|---|
| AV-TEST cumulative malware database | 1.56 billion samples | AV-TEST | March 2025 |
| Daily new malware samples | 450,000–560,000 | AV-TEST / Kaspersky | 2025 |
| Kaspersky daily detections | ~500,000 | Kaspersky telemetry | Nov 2024–Oct 2025 |
| Never-before-seen variants (2024) | 210,000+ | SonicWall 2025 Cyber Threat Report | 2024 |
| Malware-free initial access | 79% | CrowdStrike Global Threat Report 2025 | 2024 |
| Malware-free initial access H1 2025 | 81% | CrowdStrike | H1 2025 |
| Malware-free initial access in 2019 | 40% | CrowdStrike historical | 2019 |
| Infostealer credentials stolen 2025 | 1.8 billion | Flashpoint / DeepStrike | 2025 |
| Infostealer-infected devices 2025 | 5.8 million | Flashpoint / DeepStrike | 2025 |
| Infostealer credentials stolen 2024 | 3.9 billion | KELA Infostealer Epidemic Report | 2024 |
| Infostealer-infected devices 2024 | 4.3 million | KELA | 2024 |
| Avg cookies per infostealer infection | 1,861 | KELA 2024 | 2024 |
| Ransomware victims preceded by stealer logs | 54% | Verizon DBIR 2025 | 2025 |
| Days from stealer log to ransomware (typical) | 2 days | Verizon DBIR 2025 | 2025 |
| Lumma infections (Mar–May 2025) | 394,000 | Microsoft Disruption Report | May 2025 |
| RedLine share of infostealers 2020–2023 | 51% | Kaspersky | 2020–2023 |
| Top 3 stealers share of infections 2024 | 75%+ | KELA | 2024 |
| Recorded Future H2 vs H1 2025 credential growth | +50% | Recorded Future Identity Report | 2025 |
| Trojans share of all malware | ~58% | AV-TEST / StationX | 2025 |
| Ransomware share of all malware | ~14% | AV-TEST / StationX | 2025 |
| Ransomware victims YoY growth | ~40% | ESET H1 2025 | 2025 |
| ClickFix surge H1 vs H2 2024 | +500% | ESET Threat Report H1 2025 | H1 2025 |
| ClickFix share of all blocked attacks | ~8% | ESET Threat Report H1 2025 | H1 2025 |
| Exploit window: CVE to active exploit | 4 days (75% of cases) | SonicWall 2025 | 2025 |
| Average patch time (organizations) | 120–150 days | SonicWall 2025 | 2025 |
| CISA KEV additions in 2025 | 245 | CISA | 2025 |
| CISA KEV total cumulative | 1,484 | CISA | End 2025 |
| CISA KEV flagged for ransomware groups | 24 | CISA | 2025 |
| Polymorphic malware share 2026 | ~90% | Various | 2026 |
| AI-enhanced new malware samples | 37% | Various | 2026 |
| Kaspersky mobile attacks blocked 2025 | 14M+ | Kaspersky Mobile Threat Report | 2025 |
| Mobile banking trojan attacks YoY | +56% | Kaspersky press release | 2025 vs 2024 |
| Mobile banking trojan packages 2025 | 255,090 | Kaspersky Mobile Threat Report | 2025 |
| NFC-related threat growth H2 2025 | +87% | ESET Threat Report H1 2025 | H2 2025 |
| Android attacks H1 2025 vs H1 2024 | +29% | Kaspersky H1 2025 | H1 2025 |
| Global average breach cost 2025 | $4.44M | IBM Cost of a Data Breach 2025 | 2025 |
| Healthcare average breach cost 2025 | $7.42M | IBM Cost of a Data Breach 2025 | 2025 |
| Manufacturing share of malware incidents | 34.7% | Various | 2026 |
| Access broker ad volume YoY increase | +50% | CrowdStrike Global Threat Report 2025 | 2024 |
| Interactive intrusion campaign increase | +35% | CrowdStrike Global Threat Report 2025 | 2024 |
| MTAI™ Q2 2026 composite score | 82.6/100 | Axis Intelligence Research | Q2 2026 |
Methodology
Axis Intelligence Research compiled this dataset from the following primary sources:
Primary quantitative sources: AV-TEST Malware Statistics database (March 2025); Kaspersky Mobile Threat Report 2025 (Securelist, March 2026) and H1 2025 mobile statistics; CrowdStrike Global Threat Report 2025; ESET Threat Report H1 2025 (June 2025); SonicWall 2025 Cyber Threat Report / SonicWall 2026 Cyber Protect Report; IBM Cost of a Data Breach Report 2025; Verizon Data Breach Investigations Report 2025; KELA Infostealer Epidemic Report 2024; Recorded Future Identity Threat Landscape Report (March 2026); Microsoft Lumma Stealer Disruption Report (May 2025); Mandiant M-Trends 2026; CISA Known Exploited Vulnerabilities catalog (2025); AV-Comparatives Malware Protection Test March 2026; Flashpoint credential theft reporting 2025; Sophos Active Adversary 2025.
MTAI™ methodology: Five-dimension weighted composite. Dimension weights are fixed for the calendar year. Sub-scores derive from quantitative inputs updated from primary sources at each quarter-end. The 82.6/100 reading reflects Q2 2026 inputs. Full methodology: axis-intelligence.com/malware-statistics/.
Data limitations: Daily malware sample figures vary between vendors due to telemetry scope and definition of “malware sample” versus PUA. Infostealer credential counts measure disclosed logs and are structural undercounts — most infected devices are never reported. CrowdStrike’s “malware-free” figure describes the composition of detections by their IR and telemetry systems, not global prevalence. KELA and Flashpoint figures measure different credential-market data sources and are not directly additive. AV lab test results reflect controlled conditions; real-world detection rates are lower due to zero-day variants, encrypted delivery, and evasion.
About This Dataset
License: Creative Commons Attribution 4.0 (CC BY 4.0) Update cadence: Annually; quarterly MTAI™ update Citation format:
- APA: Axis Intelligence Research & Chen, M. (2026). Malware Statistics 2026. axis-intelligence.com. https://axis-intelligence.com/malware-statistics/
- MLA: Axis Intelligence Research and Marcus Chen. “Malware Statistics 2026.” Axis Intelligence, 21 June 2026, axis-intelligence.com/malware-statistics/.
- Chicago: Axis Intelligence Research and Marcus Chen. “Malware Statistics 2026.” Axis Intelligence, June 21, 2026. https://axis-intelligence.com/malware-statistics/.
Download dataset: malware-statistics.csv
Frequently Asked Questions
How much malware exists in 2026?
AV-TEST‘s cumulative malware database surpassed 1.56 billion known samples as of March 2025. Between 450,000 and 560,000 new malicious files are detected daily globally, per AV-TEST and Kaspersky telemetry. SonicWall documented over 210,000 never-before-seen variants in 2024 alone — threats that bypass signature detection on first contact.
What is the most common type of malware in 2026?
By detection volume, trojans account for approximately 58% of all malware, followed by ransomware (14%), worms (10%), adware (8%), and spyware (6%). On mobile devices, adware dominates at 62% of detections. By business impact, infostealers are the most consequential category — they power the credential-theft pipeline that enables most ransomware attacks.
How many credentials did malware steal in 2025?
Infostealer malware stole approximately 1.8 billion credentials from roughly 5.8 million infected devices in 2025, per Flashpoint and DeepStrike reporting. Recorded Future’s separate tracking found 1.95 billion malware combo list credential exposures in 2025. The 2024 figure from KELA’s Infostealer Epidemic Report was 3.9 billion credentials from 4.3 million devices.
What is ClickFix malware?
ClickFix is a social-engineering delivery technique, not a malware family. It displays a fake error — a broken CAPTCHA, a failed document render, a fake browser update — and instructs the user to copy and paste a command into their terminal to “fix” the problem. That command executes malicious code directly, bypassing email security and file-based endpoint detection. Per ESET’s H1 2025 Threat Report, ClickFix surged 500% versus H2 2024, accounting for approximately 8% of all blocked attacks.
How quickly do attackers exploit new vulnerabilities?
SonicWall’s 2025 Cyber Threat Report found that 75% of active exploits are launched within four days of CVE disclosure. Organizations take an average of 120–150 days to apply patches. That 4-day-versus-4-month gap is the operational window ransomware operators exploit most aggressively.
Is malware getting harder to detect?
In controlled lab tests, leading AV products detect over 99.95% of known malware (AV-Comparatives 2025; AV-TEST June 2025). The word “known” is doing all the work. SonicWall’s 210,000 never-before-seen variants evade signature detection on first contact, and CrowdStrike found 79% of intrusions are now malware-free — using valid credentials and living-off-the-land rather than dropped files. Traditional signature detection is necessary but not sufficient.
What is the Axis Intelligence MTAI™?
The Malware Threat Acceleration Index (MTAI™) is Axis Intelligence Research’s proprietary cross-source composite measuring the rate at which the malware threat environment is escalating across five weighted dimensions: volume acceleration, credential-theft yield, delivery sophistication, mobile attack surface, and AI-malware integration. The Q2 2026 score of 82.6/100 is the highest since the index’s 2022 inception.
What malware threatens mobile devices most in 2026?
Banking trojans are the fastest-growing mobile threat category — up 56% in 2025 overall (Kaspersky), and nearly 4× in H1 2025 versus H1 2024. The Mamont banking trojan alone accounts for approximately 49.8% of all mobile banking attack apps. NFC relay attacks — which enable ATM withdrawals and contactless payment theft via compromised Android devices — grew 87% in H2 2025 (ESET). Preinstalled trojans like Triada pose a supply-chain risk: malware embedded before the device reaches the buyer.
Others Pages
- Cybersecurity Statistics 2026 — breach costs, DBIR data, the full threat landscape
- Ransomware Statistics 2026 — ransomware economics, Qilin, RaaS model
- Phishing Statistics 2026 — PLAI™, FBI IC3, AI-generated phishing
- Social Engineering Statistics 2026 — SEII™, Mandiant M-Trends, 22-second threshold
- Cybersecurity Jobs Statistics 2026 — CWPI™, 514K open positions, workforce gap
