Finance.Yahoo Malware Activity Quadruples, Overtakes Phishing as Leading DNS Threat
Article Content
- •Malware activity quadrupled, reaching 32.6 million daily hits in April 2026.
- •Malware has overtaken phishing as the leading DNS threat category.
- •DGA activity serves as an early warning signal for upcoming malware surges.
EfficientIP's H1 2026 DNS Threat Intelligence Report reveals that malware activity has surged, quadrupling since January and surpassing phishing as the top DNS-based threat. Daily malware activity increased from 8 million hits in January to 32.6 million in April, with a total of 3.84 billion hits recorded in H1 2026. The overall DNS threat signals rose by 24% from H2 2025, indicating a significant escalation in cyber threats. The report highlights that domain-generation algorithm (DGA) activity served as an early warning signal, with notable increases in DGA activity observed in February, followed by a spike in newly observed domains in March and April. The findings emphasize the evolving threat landscape, with logistics and courier phishing also seeing a 3.4x increase, moving from seventh to third place among threats. EfficientIP analyzed over 150 billion DNS transactions to compile these insights.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track BaitHook and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is the current malware activity level?
How does DGA activity relate to malware surges?
What other threats are increasing?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…