IT threat evolution in Q2 2026. Non-mobile statistics
In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, accounting for 14.57% of all ransomware victims on data leak sites, alongside Akira and DragonForce. Microsoft successfully dismantled a malware-signing-as-a-service (MSaaS) operation run by Fox Tempest, while Check Point faced zero-day exploitation of CVE-2026-50751 by Qilin and CVE-2026-50752. Significant trends included a rise in miner variants (almost doubling compared to last quarter), increased attacks targeting macOS via vulnerabilities like FlutterShell and Coruna exploit kit, and a continued dominance of Mirai and Prometei botnets in IoT attacks. The Netherlands, Germany, and the United States led in SSH-based attacks, while Pakistan saw a notable increase in Telnet-based attacks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
