IN Q2 2026, Kaspersky reported nearly 400 million blocked cyberattacks, including 52 million unique links and 16 million malicious files. The emergence of 2538 new ransomware variants affected over 71,000 users. Ransomware activity was primarily driven by the Qilin group, with significant disruptions reported from Microsoft dismantling a malware-signing service utilized by various ransomware operators.
Additionally, Kaspersky identified 6067 new miner variants, affecting over 213,000 users, with notable attacks on macOS through malicious extensions and supply chain compromises. IoT threats continued to be dominated by Mirai botnet variants, with significant SSH-based attacks reported from the Netherlands, Germany, and the United States. The top three countries facing the highest cyber risks for web-based attacks were Bangladesh, India, and Tajikistan, while local infections were highest in Turkmenistan and Cuba.