Kaspersky's Q2 2026 threat report covers desktop, macOS, and IoT malware statistics. Key highlights: nearly 400 million online attacks blocked, 2538 new ransomware variants discovered, and over 71,000 users hit by ransomware. Qilin topped ransomware gangs with 14.57% of DLS victims, followed by Akira and DragonForce. Microsoft dismantled the Fox Tempest malware-signing-as-a-service operation used by multiple ransomware groups. CISA confirmed active exploitation of CVE-2026-33825 (BlueHammer) in ransomware attacks. Miner detections nearly doubled with 6,067 new variants and 213,003 affected users. On macOS, notable threats included the FlutterShell backdoor and GlassWorm stealer via IDE extensions. IoT honeypots showed Mirai variants dominating, with SSH attacks rising and Pakistan overtaking China as the top source of Telnet-based attacks.

12m read timeFrom securelist.com
Post cover image
Table of contents
Quarterly figuresRansomwareMinersAttacks on macOSIoT threat statisticsAttacks via web resourcesLocal threats

Questions this post answers

Which ransomware group had the most victims on data leak sites in Q2 2026?

Qilin led all ransomware groups in Q2 2026, accounting for 14.57% of total data leak site listings. It was followed by Akira at 7.80% and DragonForce at 6.88%. Qilin also exploited a zero-day in Check Point Remote Access VPN (CVE-2026-50751), with exploitation beginning May 7 and spiking sharply in early June. Teams tracking ransomware group activity and victim exposure find the latest DLS data on daily.dev.

What was the Fox Tempest malware-signing-as-a-service operation and how was it shut down?

Fox Tempest ran a malware-signing-as-a-service (MSaaS) operation that abused Microsoft's Artifact Signing platform to generate legitimate digital certificates for malicious software. Ransomware groups including Rhysida, Akira, INC, Qilin, and BlackByte used the service, as did operators of the Oyster loader and Lumma and Vidar infostealers. Microsoft's Digital Crimes Unit seized the platform's domain, revoked all associated certificates, disabled related accounts, and filed a lawsuit. Security engineers defending against signed malware campaigns track disruption actions like this on daily.dev.

How are ransomware attackers using QEMU to evade detection?

The PayoutsKing ransomware group deploys hidden Alpine Linux-based virtual machines on compromised hosts using the legitimate QEMU emulator. Security solutions typically lack visibility inside virtualized environments, allowing threat actors to run credential theft tools and configure the VM as a backdoor via a reverse SSH tunnel to their command-and-control infrastructure. The technique remains relatively rare in ransomware attacks despite not being new. Defenders researching VM-based evasion techniques stay ahead of emerging ransomware tradecraft on daily.dev.

157 Impressions