---
title: "Desktop and IoT threat statistics for Q2 2026"
url: https://daily.dev/posts/desktop-and-iot-threat-statistics-for-q2-2026-c6itziiua
source_url: https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960
type: article
source: "Securelist"
published: 2026-08-10T10:02:06.133Z
updated: 2026-08-24T06:59:35.562Z
tags: ["security", "malware", "ransomware", "kaspersky"]
reading_time: 12
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Desktop and IoT threat statistics for Q2 2026

**[Securelist](https://daily.dev/sources/securelist)** · 12 min read · 0 upvotes · 0 comments

## Summary

Kaspersky's Q2 2026 threat report covers desktop, macOS, and IoT malware statistics. Key highlights: nearly 400 million online attacks blocked, 2538 new ransomware variants discovered, and over 71,000 users hit by ransomware. Qilin topped ransomware gangs with 14.57% of DLS victims, followed by Akira and DragonForce. Microsoft dismantled the Fox Tempest malware-signing-as-a-service operation used by multiple ransomware groups. CISA confirmed active exploitation of CVE-2026-33825 (BlueHammer) in ransomware attacks. Miner detections nearly doubled with 6,067 new variants and 213,003 affected users. On macOS, notable threats included the FlutterShell backdoor and GlassWorm stealer via IDE extensions. IoT honeypots showed Mirai variants dominating, with SSH attacks rising and Pakistan overtaking China as the top source of Telnet-based attacks.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960>

## Questions this post answers

### Which ransomware group had the most victims on data leak sites in Q2 2026?

Qilin led all ransomware groups in Q2 2026, accounting for 14.57% of total data leak site listings. It was followed by Akira at 7.80% and DragonForce at 6.88%. Qilin also exploited a zero-day in Check Point Remote Access VPN (CVE-2026-50751), with exploitation beginning May 7 and spiking sharply in early June.

_Teams tracking ransomware group activity and victim exposure find the latest DLS data on daily.dev._

### What was the Fox Tempest malware-signing-as-a-service operation and how was it shut down?

Fox Tempest ran a malware-signing-as-a-service (MSaaS) operation that abused Microsoft's Artifact Signing platform to generate legitimate digital certificates for malicious software. Ransomware groups including Rhysida, Akira, INC, Qilin, and BlackByte used the service, as did operators of the Oyster loader and Lumma and Vidar infostealers. Microsoft's Digital Crimes Unit seized the platform's domain, revoked all associated certificates, disabled related accounts, and filed a lawsuit.

_Security engineers defending against signed malware campaigns track disruption actions like this on daily.dev._

### How are ransomware attackers using QEMU to evade detection?

The PayoutsKing ransomware group deploys hidden Alpine Linux-based virtual machines on compromised hosts using the legitimate QEMU emulator. Security solutions typically lack visibility inside virtualized environments, allowing threat actors to run credential theft tools and configure the VM as a backdoor via a reverse SSH tunnel to their command-and-control infrastructure. The technique remains relatively rare in ransomware attacks despite not being new.

_Defenders researching VM-based evasion techniques stay ahead of emerging ransomware tradecraft on daily.dev._

## Similar posts on daily.dev

- [Desktop and IoT threat statistics for Q1 2026](https://daily.dev/posts/desktop-and-iot-threat-statistics-for-q1-2026-udjq1acjk) · Securelist · 0 upvotes · 0 comments
- [Desktop and IoT threat report for Q2 2025](https://daily.dev/posts/desktop-and-iot-threat-report-for-q2-2025-iesxoqlu1) · Securelist · 1 upvotes · 0 comments
- [Ransomware Attacks Surge 50% In 2025, Qilin Leads Wave](https://daily.dev/posts/ransomware-attacks-surge-50-in-2025-qilin-leads-wave-ukr8h9jqa) · Cyble · 1 upvotes · 0 comments
- [Ransomware Groups Surge In Q4 2025 – Cyble Insights](https://daily.dev/posts/ransomware-groups-surge-in-q4-2025-cyble-insights-bekvw1yk1) · Cyble · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware), [#ransomware](https://daily.dev/tags/ransomware), [#kaspersky](https://daily.dev/tags/kaspersky)

[View this post on daily.dev](https://daily.dev/posts/desktop-and-iot-threat-statistics-for-q2-2026-c6itziiua)
