Most security teams learn about a malware wave the hard way: alerts spike, endpoints light up, and the incident response clock starts. But new research suggests the warning signs were sitting in DNS logs weeks earlier, for anyone looking in the right place.
EfficientIP's H1 2026 DNS Threat Intelligence Report, built on analysis of more than 150 billion DNS transactions a day, finds that malware has overtaken phishing as the leading DNS-based threat category. Daily malware activity roughly quadrupled between January and April. And the infrastructure behind that surge started taking shape a full month before the surge itself.
Comparing H2 2025 with H1 2026, EfficientIP found that total threat-signal volume rose 24%, from 11.18 billion to 13.85 billion hits. Malware drove much of that growth, nearly doubling (1.97x) to 3.84 billion hits and jumping from fourth place to first, with 27.7% of all threat signals.
The month-by-month curve is what stands out:
November 2025: Malware peaked for the half at 14.4 million hits per day.
January 2026: Activity fell to a low of 8.0 million per day.
March: Back up to 16.2 million per day.
April: Doubled again to 32.6 million per day.
May–June: Held between 29 and 32 million per day, above every month of H2 2025.
Malware wasn't the only fast mover. Hits on domains first seen within the past day (what EfficientIP calls NOD_1d) also doubled, to 530 million. Botnet activity grew 1.86×. Meanwhile, phishing declined 10% to 2.48 billion hits, still a massive volume, but no longer the top of the list.
The report's most useful finding for defenders is a sequence.
Domain generation algorithms (DGAs) let malware churn out large numbers of pseudo-random domains to locate its command-and-control servers. That makes DGA activity a proxy for attacker infrastructure coming online. In H1 2026, the signals arrived in order:
February: DGA activity rose 24.2% month over month, the first sign of new infrastructure.
March: Domains newly observed within the prior seven days climbed 56.8%, while malicious activity jumped 73.1%.
April: Both peaked together, with newly observed domains up 92.1% and malicious activity up 86.8%, the same month malware hit its high for the half.
In other words, the runway was built in February; the planes took off in March and April.
EfficientIP frames the two signals as complementary rather than redundant. DGA gives an earlier view of infrastructure being stood up; newly-observed domain activity tracks closely with the rise and fall of active malicious operations.
"Malware's rise to the top of the threat landscape should concern every security team," said Karim Hossen, R&D Manager and CISO at EfficientIP. "Suspicious DNS activity can reveal its infrastructure weeks before an attack unfolds, giving defenders time to investigate and act."
The report tracks 187 DGA families and profiles five in detail. Each one breaks a common assumption.
BaitHook: Persistence is quiet
Tracked since 2025, BaitHook averaged about 4,500 observed device matches per day across the half, rising to roughly 5,500 in June. Its 335 command-and-control (C&C) domains surfaced in small daily counts across 124 days rather than in dramatic bursts, and many of its IP addresses had been seen before. Infrastructure reuse at that scale is a gift to defenders who keep historical data.
Phobia: Gone isn't gone
Phobia hit roughly 62,000 device matches on January 15, then collapsed to 600–700 a day within 72 hours. It came back in April at around 6,000 and climbed to roughly 25,000 in May. A family that drops off a dashboard may simply be reloading.
TravelLog: Generation runs ahead of registration
First spotted through about 1,500 suspicious domains in late January and February, TravelLog uses 15-character alphanumeric .xyz domains in monthly clusters of roughly 500. Device matches peaked at 9,527 on February 18. Actual registrations came later in tight, registrar-specific batches, including 123 domains through a single registrar on March 20.
DayDream: Broad generation, narrow commitment
First observed in late April, DayDream generated around 500 domains a day across 14 top-level domains, but registered only a fraction of them, most in a single batch of 185 on May 24. Volume of generated names tells you little about which ones will actually go live.
Unmasked: Expired doesn't mean safe
Unmasked's domains were registered in mid-2025 and had expired by June 2026. No new C&C domains opened during the half. Yet after first appearing in the dataset on June 12, device matches climbed to 46,041 by June 30, making it the most active DGA family tracked by month's end. Infected devices keep calling home whether or not anyone is answering, and an expired domain can be re-registered by anyone.
Phishing volume dipped overall, but the targets rotated sharply. Online and cloud services reclaimed first place with 27.7% of detections, with Microsoft, Netflix, and Amazon all seeing more activity. Social networking collapsed from 21.1% to 7.7% as Telegram-themed activity fell back from its H2 2025 spike.
The biggest mover was logistics and courier brands, which climbed from seventh to third, with their share of detections rising 3.4x, from 4.0% to 13.6%. Much of that came from a single campaign impersonating European parcel carrier Mondial Relay that emerged in the final days of June.
With holiday shipping season approaching, EfficientIP's researchers say delivery-themed lures deserve particular attention. For U.S. teams, the specific brand matters less than the pattern: one active campaign can reshape a sector's threat profile almost overnight.
A few caveats are worth keeping in view.
This is vendor research drawn from EfficientIP's own telemetry, so it reflects what its platform sees. The company also notes that new detection techniques introduced during H1 2026 broadened visibility into crypto landing pages, delivery and banking lures, and CAPTCHA-based entry points, which means some category shifts may partly reflect better detection rather than purely more attacks.
The report is also careful on causation. It explicitly advises analyzing device matches, opened C&C domains, WHOIS records, and generation patterns together, without assuming a change in one directly causes a change in another. The February DGA uptick preceding the March–April surge is a strong correlation across one half-year, not a guaranteed forecasting model.
That said, the core argument lines up with long-standing government guidance. In their joint guidance on protective DNS, U.S. CISA and the NSA observed that "the domain names associated with malicious content are often known or knowable," and that blocking their resolution protects both users and the enterprise. The agencies specifically cited DGAs and C&C among the threats protective DNS can disrupt, and CISA has encouraged organizations to use DNS query logs for incident response and threat hunting.
Treat DNS as a sensor, not just plumbing. If DNS logs aren't flowing into your SOC's detection pipeline, the early signal in this report is invisible to you.
Baseline DGA and newly observed domain activity. A 24% month-over-month jump in DGA traffic is only meaningful if you know what normal looks like.
Don't retire indicators too early. Phobia and Unmasked both show that a quiet or expired domain family can return, and endpoints still querying dead domains are likely still infected.
Keep infrastructure history. BaitHook's IP reuse rewards teams that retain and correlate past observations.
Brief users on delivery lures now. Courier-themed phishing surged at the end of H1, right before the busiest shipping season of the year.
The most striking thing about H1 2026 isn't that malware surged; it's that the surge left footprints before it arrived. Attackers have to build infrastructure, and that infrastructure has to resolve. For security teams willing to watch DNS closely, a few weeks of warning may be the difference between a hunt and a breach.