Skip to content
EfficientIP Finds Malware Activity Quadrupled Since January, Overtaking Phishing as Top ...

EfficientIP Finds Malware Activity Quadrupled Since January, Overtaking Phishing as Top ...

Finance.Yahoo • October 7, 2026

New H1 2026 research finds attackers build domain infrastructure weeks before malware strikes

Malware jumps from No. 4 to No. 1, with daily activity up 4x since January

Malware jumps from No. 4 to No. 1, with daily activity up 4x since January

Total DNS threat signals rise 24% from H2 2025

Total DNS threat signals rise 24% from H2 2025

Logistics and courier phishing jumps 3.4x, rising from No. 7 to No. 3

Logistics and courier phishing jumps 3.4x, rising from No. 7 to No. 3

DGA activity precedes malware surges by weeks, offering an early warning signal

DGA activity precedes malware surges by weeks, offering an early warning signal

WEST CHESTER, Pa., Oct. 7, 2026 /PRNewswire/ -- EfficientIP , a leader in DNS security and DDI (DNS-DHCP-IPAM), today released its H1 2026 DNS Threat Intelligence Report , drawn from analysis of more than 150 billion daily DNS transactions. The report found malware overtook phishing as a leading DNS-based threat category, climbing from fourth place in H2 2025 to first in H1 2026 as daily activity roughly quadrupled between a January low of 8.0 million hits per day and an April peak of 32.6 million, holding near that level through June.

Total threat-signal volume across all categories rose 24% from H2 2025, from 11.18 billion to 13.85 billion hits. Malware itself nearly doubled over the same period, reaching 3.84 billion hits and accounting for much of that overall increase. The report also traces a clear escalation sequence in the underlying DNS data, showing that attackers were building the infrastructure for the malware surge weeks before it launched:

February: Domain-generation algorithm (DGA) activity strengthened first, rising 24.2% month over month, the earliest sign that new infrastructure was coming online.

February: Domain-generation algorithm (DGA) activity strengthened first, rising 24.2% month over month, the earliest sign that new infrastructure was coming online.

March: Newly observed domains climbed 56.8% as malicious activity itself began accelerating, up 73.1% for the month.

March: Newly observed domains climbed 56.8% as malicious activity itself began accelerating, up 73.1% for the month.

April: Both signals peaked together. Newly observed domains rose another 92.1%, malicious activity 86.8%, the point at which malware activity reached its high for the half.

April: Both signals peaked together. Newly observed domains rose another 92.1%, malicious activity 86.8%, the point at which malware activity reached its high for the half.

The report also profiles five DGA families in detail. Three show distinct patterns in how attackers registered, queried and reused their domains:

Unmasked kept drawing DNS queries to its domains after their registrations had expired, then became the most active DGA family tracked by the end of June, underscoring that an expired registration does not eliminate the risk a domain poses.

Unmasked kept drawing DNS queries to its domains after their registrations had expired, then became the most active DGA family tracked by the end of June, underscoring that an expired registration does not eliminate the risk a domain poses.

BaitHook , tracked since 2025, stayed persistently active and showed heavy reuse of previously observed IP infrastructure.

BaitHook , tracked since 2025, stayed persistently active and showed heavy reuse of previously observed IP infrastructure.

Phobia surged to roughly 62,000 daily device matches in mid-January, dropped to near-zero within days, then returned in April and climbed again through May, illustrating that a sharp drop-off does not necessarily mean a family has gone dark.

Phobia surged to roughly 62,000 daily device matches in mid-January, dropped to near-zero within days, then returned in April and climbed again through May, illustrating that a sharp drop-off does not necessarily mean a family has gone dark.

Phishing tells a different story: overall volume declined 10%, but targets rotated sharply across sectors. Logistics and courier brands climbed from the seventh most-targeted sector to third, with their of detections rising 3.4x, from 4.0% to 13.6%, largely on the strength of a single active campaign that emerged in late June. With holiday shipping volumes approaching, EfficientIP's researchers say delivery and courier-themed lures warrant particular attention from security teams in the coming months.

"Malware's rise to the top of the threat landscape should concern every security team," said Karim Hossen, R&D Manager and CISO at EfficientIP. "Suspicious DNS activity can reveal its infrastructure weeks before an attack unfolds, giving defenders time to investigate and act."

The full H1 2026 DNS Threat Intelligence Report is available here.

EfficientIP EfficientIP is a global specialist in DNS, DHCP and IP Address Management (DDI) and DNS security solutions. Its integrated platform helps organizations automate network services, strengthen cybersecurity, improve operational efficiency and ensure the availability of critical applications and digital services. Founded in 2004 and headquartered in Paris, EfficientIP serves more than 1,800 customers worldwide across industries including financial services, telecommunications, energy, retail, education and the public sector, with operations spanning Europe, North America, the Middle East and Asia-Pacific. For further information, please visit efficientip.com .

PR for EfficientIP [email protected]

View original content to download multimedia:

Extracted Entities