Malware Activity: Key Statistics Quarter over Quarter comparison: July 1,2026 - September 30,2026

Each reporting period, we analyze URLs, domain names, and IP addresses reported for serving up or distributing malware. We use these and other metadata — domain and IP address registration data, ICANN registry and registrar monthly reports, routing data, attack type, and other indicators — to report key statistics for each reporting period.

We compare number of domains reported for hosting malware in TLDs for two consecutive quarters in the table below.

Complete lists of Top-level Domains, gTLD registrars and hosting networks (ASNs) where malware was reported for the quarter can be downloaded in CSV format from the Records page.

Measurement April to June 2026 July to September 2026 Change
in
Measurement
Total number of malware reports collected from feeds (per quarter) 983,446 1,102,198 118,752
Total number of malware records produced from malware reports 764,141 928,384 164,243
Endpoint malware (targets user-attended devices) 65,848 46,271 -19,577
Internet of Things (IoT) malware (targets sensors, wearables, appliances...) 30,817 28,706 -2,111
Malicious IP address malware records (Traffic Injectors and Attackware) 578,273 766,674 188,401
Uncategorized malware (Verified as malware but not classified) 89,203 86,733 -2,470
Unique domain names reported for serving up malware 31,139 46,354 15,215
Top-level Domains (TLDs) where we observed malware hosting 343 444 101
Registrars that had gTLD domains under management reported for serving malware 384 395 11
Hosting Networks (ASNs) where we observed malware hosting or distribution 18,076 19,938 1,862
Unique IPv4 addresses reported as serving or distributing malware 592,094 781,292 189,198