Rise of Malware: A Review of EfficientIP's DNS Threat Report
EfficientIP's H1 2026 DNS Threat Intelligence Report
EfficientIP has unveiled its latest H1 2026 DNS Threat Intelligence Report, revealing a significant increase in malware activity that has now overtaken phishing as the primary DNS-based threat. The comprehensive analysis draws from over 150 billion DNS transactions daily and highlights a worrying trend that security teams must be aware of.
In the report, malware has jumped from the fourth position in H2 2025 to the top spot in H1 2026, with daily incidents rising from a low of 8.0 million hits at the beginning of January to a staggering 32.6 million by April. By the end of June, this number remained elevated, underlining the urgency for organizations to enhance their cybersecurity measures. The increase in total threat signals across all categories amounted to 24%, soaring from 11.18 billion to 13.85 billion hits, with malware itself nearly doubling to 3.84 billion. This highlights a major shift in the threat landscape, which needs to be taken seriously by all security personnel.
Trends and Insights from the Report
The report indicates a clear escalation pattern in DNS data indicating malicious activity. Beginning in February, Domain Generation Algorithm (DGA) activities became evident with a month-over-month rise of 24.2%. This served as an early warning sign of the impending surge, followed by a notable 56.8% increase in newly observed domains in March, correlating with a 73.1% uptick in malicious actions during the same timeframe. By April, both indicators peaked simultaneously, with new domains jumping 92.1% and malicious activity rising 86.8%. This correlation points to a well-structured approach by attackers in preparing the infrastructure required for the malware rollout.
The report highlights five distinct DGA families, focusing on their characteristics and actions:
1. Unmasked: This family saw a significant amount of DNS queries directed to expired domains, demonstrating that even after expiration, these domains can remain a threat.
2. BaitHook: Active since 2025, this family showed considerable reuse of previously identified IP infrastructure, indicating persistence in their operations.
3. Phobia: This family exhibited a rapid escalation in activity, peaking at about 62,000 daily matches in mid-January, then experienced a sharp decline before re-emerging in April and surging again in May.
Interestingly, while malware saw an upward trend, the phishing sector experienced a 10% decline overall. Nevertheless, certain sectors such as logistics and courier gained significant attention, increasing from the seventh to the third most targeted industry, largely due to a single active campaign that emerged in June. This emphasizes the need for security teams to be vigilant, especially as the holiday shipping season approaches, indicating rising threats using delivery and courier-themed scams.
Expert Commentary
Karim Hossen, the RD Manager and CISO at EfficientIP, expressed his concern regarding malware's rise. He indicated, "Malware's ascent to the top of the threat landscape should alert every security team. Suspicious DNS activity can provide crucial alerts weeks before an attack happens, giving defenders the necessary time to act and mitigate risk."
Conclusion
EfficientIP's H1 2026 DNS Threat Intelligence Report paints a concerning picture of the current threat landscape, where malware activity has quadrupled and overshadowed phishing. Organizations must stay informed of these trends, adjust their cybersecurity strategies accordingly, and fortify their defenses against emerging threats. Continuous vigilance and timely defensive actions can significantly reduce the potential impact of such growing malware risks. To access the full report and dive deeper into the findings, visit EfficientIP's official website.
About EfficientIP
EfficientIP is a global leader in DNS security and DDI (DNS, DHCP, and IP Address Management) solutions. Since its founding in 2004, it has helped organizations across various sectors, including financial services, telecommunications, and public services, improve their network services and cybersecurity measures. Headquartered in Paris, EfficientIP operates worldwide, with over 1,800 customers benefiting from its innovative technologies.