Skip to main content

Cybersecurity statistics / Malware

The most prevalent malware families observed in 2025 are Cobalt Strike, Sliver, Metasploit, Burp, PlugX, SuperShell C2, Havoc, Panda C2, Brute Ratel, and ShadowPad.

PublisherBridewell
ReportCyber Threat Intelligence Report 2026
Published18 May 2026
TopicsMalware , Cobalt Strike, Sliver, Metasploit, Burp

Published by Bridewell in Cyber Threat Intelligence Report 2026 , 18 May 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

China hosted 42.3% of all tracked Cobalt Strike infrastructure, the US hosted 18.9%, and Hong Kong hosted 15.8%.
Bridewell, 27/05/2026
Cobalt Strike accounted for 38.4% of all OST output (3,944 of 10,272 tracked OST instances), maintaining its position as the primary adversary framework.
Bridewell, 27/05/2026
PowerShell was the primary attack vector with 96,061 detections by Trellix, followed by Cobalt Strike with 85,986 detections targeting the IT-to-OT boundary.
Trellix, 22/11/2025
China remained the second largest adversary infrastructure hosting location at 13.55%, down from 17.57% the previous year.
Bridewell, 27/05/2026
Germany increased to 8.74%, becoming the third largest adversary infrastructure hosting location and overtaking both Hong Kong (7.22%) and the Netherlands (6.51%).
Bridewell, 27/05/2026
WhiteSnake Stealer was the most widely observed infostealer family, accounting for 31.6% of all tracked output, followed by RedLine at 23.9%, Rhadamanthys at 17.1%, and StealC at 6.9%.
Bridewell, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.