Malware remains one of the most persistent cyber risks in the world, and the latest available industry data shows that ransomware, malicious file attachments, credential theft, and mobile malware are all still growing problems. The numbers below bring together recent findings from AV-TEST, Verizon, the FBI, OpenText, SonicWall, and Kaspersky to show where malware is hitting hardest and how attack patterns are shifting.

Key malware statistics
- AV-TEST says more than 450,000 new malicious programs and potentially unwanted applications are registered every day.
- Verizon analyzed 22,052 security incidents and 12,195 confirmed breaches in its 2025 DBIR, the highest breach count it has ever analyzed in one report.
- Ransomware was present in 44% of the breaches Verizon reviewed.
- Among SMBs in Verizon’s dataset, 88% of breaches involved ransomware.
- Among larger organizations in Verizon’s dataset, ransomware appeared in 39% of breaches.
- Credential abuse accounted for 22% of known initial access vectors in non-error, non-misuse breaches.
- Exploitation of vulnerabilities accounted for 20% of known initial access vectors, while phishing accounted for 16%.
- The FBI received 3,156 ransomware complaints in 2024, up from 2,825 in 2023 and 2,385 in 2022.
- OpenText reported a 2.39% malware infection rate on business PCs in 2024, up more than 28% year over year.
- OpenText reported a 3.07% malware infection rate on consumer devices in 2024.
- SonicWall found that 38% of malicious files it detected were HTML-based, while 22% were PDFs.
- Kaspersky reported 29% more attacks on Android smartphone users in the first half of 2025 than in the first half of 2024.
Ransomware is still the clearest malware signal in breach data
Ransomware continues to dominate the malware conversation because it combines disruption, extortion, and data theft in a single event. Verizon’s latest breach data shows that ransomware is not just common overall. It is especially concentrated in smaller organizations.
Ransomware share of breaches in Verizon’s 2025 DBIR
| Label | Bar | Value | ||
|---|---|---|---|---|
| SMB breaches |
| 88% | ||
| All breaches |
| 44% | ||
| Larger organizations |
| 39% |
Max = 88. Widths: SMB breaches 100.00%, All breaches 50.00%, Larger organizations 44.32%.
The same Verizon report also notes that 64% of victim organizations did not pay the ransom, which suggests some improvement in resilience even as ransomware keeps spreading. For defenders, that makes preparation, segmentation, and recovery planning just as important as prevention.
Credential abuse, unpatched systems, and phishing still drive malware-linked breaches
Malware rarely appears out of nowhere. It usually enters through stolen credentials, an exploited vulnerability, or a social engineering event that gets a user to open the door. Verizon’s initial access data shows that those three routes remain the main gateways.
Top known initial access vectors in Verizon’s 2025 DBIR
| Label | Bar | Value | ||
|---|---|---|---|---|
| Credential abuse |
| 22% | ||
| Exploitation of vulnerabilities |
| 20% | ||
| Phishing |
| 16% |
Max = 22. Widths: Credential abuse 100.00%, Exploitation of vulnerabilities 90.91%, Phishing 72.73%.
That matters because malware prevention is no longer just an antivirus problem. It is also a patching problem, an identity problem, and a user training problem. Verizon also found only about 54% of edge-device and VPN vulnerabilities were fully remediated during the year, with a median remediation time of 32 days.
FBI complaint data shows ransomware is still moving upward
One useful way to track malware pressure is to watch complaint volumes over time. FBI IC3 complaint totals are not the same thing as total attack volume worldwide, but they do show that ransomware remains highly active and still trending in the wrong direction.
FBI IC3 ransomware complaints by year
| Label | Bar | Value | ||
|---|---|---|---|---|
| 2024 |
| 3,156 | ||
| 2023 |
| 2,825 | ||
| 2022 |
| 2,385 |
Max = 3156. Widths: 2024 100.00%, 2023 89.51%, 2022 75.57%.
The FBI also reported 263,455 cyber threat complaints in 2024, $1.571 billion in losses, and 4,878 complaints from critical infrastructure organizations. Ransomware and data breaches were the most reported cyber threats among critical infrastructure organizations.
Endpoint infection rates are rising again
OpenText’s endpoint telemetry suggests that infection pressure is moving back up, especially on business devices. Consumer devices still show the higher overall infection rate, but the sharper year-over-year deterioration is on the business side.
OpenText malware infection rates in 2024
| Label | Bar | Value | ||
|---|---|---|---|---|
| Consumer devices |
| 3.07% | ||
| Business PCs |
| 2.39% |
Max = 3.07. Widths: Consumer devices 100.00%, Business PCs 77.85%.
OpenText also found that business PCs saw 73.8% of all new files encountered across its dataset, versus 26.2% for consumer devices. That helps explain why malware on managed and unmanaged work devices remains a high-priority enterprise risk.
HTML files and PDFs remain major malware delivery formats
Malware is not just about the payload. The wrapper matters too. SonicWall’s latest threat report shows how heavily attackers lean on everyday file types that users already trust.
Share of malicious files detected by SonicWall
| Label | Bar | Value | ||
|---|---|---|---|---|
| HTML-based files |
| 38% | ||
| PDF files |
| 22% |
Max = 38. Widths: HTML-based files 100.00%, PDF files 57.89%.
This is one reason malware defense now overlaps so heavily with phishing defense. When a familiar file type is the lure, users are more likely to open it, and attackers get a better chance to steal credentials, drop loaders, or redirect victims to fake login pages.
Mobile malware is still climbing
Kaspersky reported that attacks on Android smartphone users in the first half of 2025 were 29% higher than in the first half of 2024 and 48% higher than in the second half of 2024. It also said the number of mobile banking trojans detected in the first half of 2025 was almost four times the first-half 2024 level. That is a reminder that malware risk is no longer confined to desktops and servers. It is now firmly part of the mobile threat landscape as well.
Bottom line
The latest malware statistics point to the same broad conclusion: ransomware remains widespread, credential theft is still one of the main gateways to compromise, unpatched systems continue to create openings, and seemingly normal file types like HTML pages and PDFs are doing a lot of delivery work for attackers. For most organizations, the practical response is a layered one: better patching, stronger identity controls, tighter email and web filtering, improved backup discipline, and faster detection on both endpoints and mobile devices.
Sources used
- AV-TEST malware statistics
- Verizon 2025 Data Breach Investigations Report Executive Summary
- FBI IC3 2024 Annual Report
- OpenText 2025 Cybersecurity Threat Report
- SonicWall 2025 Cyber Threat Report
- Kaspersky mobile malware update, September 2025