A laptop on a desk showing a security warning on screen

Cybersecurity

7 types of malware to watch out for in 2026

A staff member searches for a free PDF tool, lands on a page with a “verify you are human” box, and follows the steps on screen: press a few keys, paste, press Enter. Nothing seems to happen. In the background, they just ran a command that installed software to copy every password saved in their browser, one of the most common types of malware businesses see in 2026.

Microsoft says campaigns using that trick target thousands of devices every day. It is a fair picture of where malware has gone: less of the old virus that crashed your PC, more quiet theft of logins, abuse of tools already on the computer, and data taken before anyone notices.

Four types of malware behind most incidents

Malware is any software built to damage devices, steal data, spy on users or give an attacker control. The classic labels still apply: viruses and worms spread from file to file or device to device, trojans pose as legitimate software so you install them yourself, and spyware reports what you do. Most of it still arrives through phishing, fake downloads, poisoned search ads and unpatched software. What has changed is what attackers do once they are in.

1. Ransomware with data theft

Modern ransomware groups usually steal data first, then encrypt systems, then threaten to publish what they took if you don’t pay. Backups get you running again, but they do nothing about the leak. Planning still pays off: in Verizon’s 2026 report, 69% of ransomware victims didn’t pay, which shows good backups give you real options.

48%

of breaches in Verizon’s 2026 Data Breach Investigations Report involved ransomware, up from 44% the year before

2. Infostealers

Infostealers collect saved passwords, browser session cookies, card details and crypto wallets, then send them to the attacker. In May 2025, Microsoft led a legal action against the Lumma infostealer after identifying more than 394,000 infected Windows computers worldwide in just two months. A stolen session cookie can let an attacker into an account without the password or another MFA prompt.

3. ClickFix and fake CAPTCHA pages

This is the trick from the opening. A fake verification box or error message tells the user to paste and run a command to “fix” it, and Microsoft reports these campaigns deliver infostealers, remote access tools and loaders. No legitimate website will ever ask you to do this.

4. Fileless and “living off the land” attacks

Instead of dropping an obvious malicious file, attackers use tools already built into Windows, such as PowerShell, along with stolen credentials and legitimate remote management software. CrowdStrike’s 2026 Global Threat Report found 82% of the detections it saw were malware-free. Traditional antivirus looks for bad files, so it often sees nothing at all.

Three that hide, adapt or stay in control

The last three are harder to spot, because staying hidden is the whole job.

Glasses resting in front of a monitor showing code

5. Remote access trojans

These give an attacker hidden, ongoing control of a computer. They are a common payload from phishing and ClickFix campaigns, and they are often used to set up a ransomware attack days or weeks later.

6. Polymorphic and AI-assisted malware

Polymorphic malware changes its code each time it spreads, so signature-based scanners never see the same thing twice. Attackers are now testing AI for the same goal. In November 2025, Google’s Threat Intelligence Group described PROMPTFLUX, an experimental malware that called an AI model to rewrite its own code. Google said it was still in testing and not able to compromise devices. The direction is clear anyway: detection has to watch behavior as well as known signatures.

7. Rootkits

Rootkits bury themselves deep in the operating system to hide other malware, keep administrator access and sometimes switch off security tools. Reimaging the device is often the safest fix.

Warning signs and the first hour

A clean-looking computer proves little, since modern malware tries hard to stay invisible. Report it when you notice sudden slowness or a busy fan with nothing open, new browser extensions or home pages you didn’t add, pop-ups from software you don’t recognize, security tools that are turned off, MFA prompts you didn’t request, or clients receiving odd emails from your account. Our post on signs your computer may be infected goes into more detail.

If you suspect malware:

  1. Disconnect the device from Wi-Fi and the network, and leave it powered on so evidence isn’t lost.
  2. Call your IT provider before trying to clean it yourself. A quick scan can miss what is really there.
  3. Change passwords from a different, clean device, starting with email, banking and admin accounts, and sign out of all active sessions.
  4. Look for spread: unusual sign-ins, new mailbox rules or other devices behaving oddly.
  5. Restore or reimage from known-good backups once the cause is understood.
  6. If client, patient or financial data may have been exposed, talk to your attorney or compliance advisor about notification rules and contact your cyber insurer.

Defenses that work against all seven types of malware

No single tool stops everything on this list, so the protection has to come in layers. These are the ones that matter most:

  • Endpoint detection and response that watches behavior, backed by a security operations center that can isolate an infected device at any hour.
  • Application control, so unapproved programs and scripts can’t run even when someone is tricked into launching them.
  • Patching. Verizon’s 2026 report found exploited vulnerabilities were the most common way into breaches, at 31%.
  • MFA everywhere, with phishing-resistant methods for email and admin accounts.
  • Email filtering and DNS protection that block malicious links and attachments before anyone sees them.
  • Security awareness training that covers fake CAPTCHA and “paste this command” tricks.
  • Backups stored separately from your network, so ransomware can’t reach them.

For our clients, those layers come with our cybersecurity service. Every client has a 24/7 security operations center watching their devices and able to isolate an infected one. Admin accounts sign in with security keys or passkeys, and everyone else approves sign-ins in an app with number matching. Server backups run hourly and are copied off-site daily to immutable storage, which is the foundation of our business continuity work. For the ransomware side in more depth, see our guide on how to prevent ransomware.

Find out whether your current setup would catch an infostealer or a ClickFix command before someone clicks. Book an intro call and we can go through it together.

FAQ

Frequently asked questions

Is ransomware a type of malware?

Yes. Ransomware is malware that encrypts your files and demands payment to unlock them, and most groups now steal a copy of the data first and threaten to publish it. Verizon’s 2026 Data Breach Investigations Report found ransomware in 48% of breaches. Backups get you running again, but they do nothing about the stolen data.

What are the most common types of malware?

The ones behind most business incidents in 2026 are ransomware that steals data before encrypting it, infostealers that take saved passwords and session cookies, fake CAPTCHA (ClickFix) pages that trick people into running a command, and fileless attacks that use tools already built into Windows. Remote access trojans, polymorphic malware and rootkits complete the list. The classic viruses, worms, trojans and spyware still exist too.

Sources: Verizon, 2026 Data Breach Investigations Report; Help Net Security, Lessons from the Verizon DBIR 2026, May 2026; Microsoft Security Blog, Think before you Click(Fix), August 2025; Microsoft Security Blog, macOS ClickFix campaign, August 2026; Microsoft On the Issues, Disrupting Lumma Stealer, May 2025; CrowdStrike, 2026 Global Threat Report findings; Google Threat Intelligence Group, AI Threat Tracker, November 2025.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.