Skip to content

H1 2026 DNS Threat Intelligence: DGA as an early Malware Indicator

EfficientIP’s H1 2026 threat intelligence research shows DGA activity strengthening before the broader malware surge. Combined with other DNS signals, it can help defenders recognize emerging threat infrastructure earlier.

October 8, 2026 | Written by: Yaëlle Harel |

Summary

H1 2026 Dns Threat Intelligence Report Highlighting Dga As an Early Malware Indicator

Can You Detect an Attack While It Is Still Being Prepared? Attackers leave DNS breadcrumbs in plain sight before they strike . EfficientIP’s H1 2026 research shows how DGA activity can serve as an early Malware Indicator, helping defenders recognize emerging infrastructure

Key Takeaways

  • Malware nearly doubled compared with H2 2025, jumping from fourth to first place among threat categories as total threat signals rose 24%.
  • DGA activity strengthened before the broader malicious-activity surge, highlighting its value as an early Malware Indicator.
  • Combining DNS signals helps defenders understand how infrastructure develops and identify activity that deserves earlier investigation.

Can You Detect an Attack While It Is Still Being Prepared?

On a Sunday morning in October 2025, the Louvre museum had been open for barely half an hour when a truck equipped with a furniture lift pulled up outside. Men dressed as renovation workers set out traffic cones, raised the lift and climbed toward a gallery window.

Minutes later, they escaped on scooters with crown jewels stolen from one of the world’s most famous museums.

The preparations had unfolded in plain sight. A vehicle, equipment, people apparently going about their work. Together, they were the opening moves of a robbery.

The story raises a question that extends well beyond physical security: how do you recognize preparations for an attack while they still resemble ordinary activity?

Louvre Robbery Analogy Illustrating How Dns Threat Signals Can Reveal Malicious Infrastructure Before an Attack

Cyberattackers need infrastructure too. They generate domain names, register selected addresses and prepare systems to support malicious communications. As that infrastructure develops, it can leave breadcrumbs in DNS.

Newly observed domains appearing in DNS traffic for the first time. Devices repeatedly querying domains that do not exist. Hundreds of domain names follow the same pattern, with some later registered and activated as command-and-control infrastructure.

Each observation can have an innocent explanation. But relationships between them can reveal something worth investigating. Recognizing those relationships is what gives DNS threat intelligence its value for earlier malware detection.

EfficientIP’s H1 2026 DNS Threat Intelligence Report shows why following that trail matters — and why DGA activity can serve as an early Malware Indicator.

H1 2026: A Malware-First Threat Landscape

The H1 2026 DNS Threat Intelligence Report reveals a substantial shift in the threat landscape. Total threat signals increased 24% compared with H2 2025, rising from 11.2 billion to 13.9 billion hits. Malware nearly doubled to 3.84 billion hits and became the leading threat category, moving from fourth to first place.

H1 2026 Dns Threat Landscape Showing 24 Growth in Threat Signals 384 Billion Malware Hits and Malware Rising from Fourth to First Among Threat Categories

Other parts of the landscape shifted too. Newly observed domains nearly doubled, highlighting the continued emergence of fresh infrastructure. Phishing activity rotated sharply across sectors and brands, with Logistics & Couriers becoming one of the biggest movers. At the same time, established DGA families persisted or returned while new families emerged with different patterns of generation, registration and activity.

But one finding was particularly important for malware detection: before the strongest surge in malicious activity became visible, DNS was already leaving clues. DGA activity strengthened first, followed by an acceleration in newly observed domains as malicious activity increased.

These signals are the DNS breadcrumbs. Individually, they may reveal only part of the picture. Together, they can show how malicious infrastructure is taking shape over time.

Simplify & Secure Your Network

Our goal is to help companies face the challenges of modern infrastructures and digital transformation.

DGAs and Newly Observed Domains Are the DNS Breadcrumbs

The value of these breadcrumbs comes from the sequence in which they appear.

Domain generation algorithms (DGAs) can create large numbers of domains that malware uses to locate command-and-control infrastructure. Devices may begin querying those domains weeks or even months before some are registered or activated, leaving traces in DNS while the infrastructure is still taking shape. That is what makes DGA activity valuable as an early Malware Indicator.

Newly observed domains provide another piece of the trail. They show where fresh domain infrastructure is beginning to appear in DNS traffic and can help track how that infrastructure evolves as activity develops.

Diagram Showing How Dga Activity and Newly Observed Domains Reveal Malicious Infrastructure Before Command and control Goes Live

The two signals answer different questions. DGA activity can reveal patterns associated with infrastructure being prepared, while newly observed domains help show fresh infrastructure becoming visible and active.

Neither signal is conclusive on its own. But when DNS threat intelligence connects them with device behavior, registration activity and infrastructure relationships, the breadcrumbs begin to form a pattern.

Like the clues before the Louvre robbery, these DNS breadcrumbs can be hiding in plain sight. They are only valuable if someone is paying attention early enough to connect them before the bigger picture becomes obvious.

Beyond the Surge: What Else the Report Reveals

The malware surge is only one part of the H1 2026 picture. The DNS Threat Report also shows how quickly the threat landscape can shift beneath headline trends.

Phishing is a good example. Overall phishing activity declined, but targeting changed significantly across sectors and brands.

Which sectors moved up the rankings? Which brands drove the change? And how much of that movement came from a small number of active campaigns?

The report also looks more closely at the malware surge itself, showing how activity developed in distinct waves rather than as a single continuous rise.

And it follows five DGA families to show that there is no single DGA lifecycle. Some persist, some disappear and return, some generate far more domains than are ever registered, and some continue attracting queries even after domains have expired.

Together, the malware, phishing and DGA investigations show how much can change beneath the surface of a six-month total.

What These Changes Mean for Security Teams

The practical challenge is turning early signals into earlier action.

As with the Louvre robbery, the clues may already be visible before the main event. The difference is whether anyone is looking closely enough to connect them.

Make sure DNS monitoring captures failed lookups, repeated requests and enough history to reveal patterns over time. Then connect those signals to the devices generating them and enrich them with endpoint, network and infrastructure context.

Most importantly, define what happens next. Teams should know when an emerging pattern stays under observation, when it triggers investigation and when it justifies protective action.

One question can expose the gap:

If several devices repeatedly queried a related group of domains that did not resolve, would your SOC recognize the pattern and know what to do next?

For security leaders, the measure of useful DNS threat intelligence is simple: did it help connect the dots and bring the investigation forward?

How EfficientIP Connects the Signals

The report’s findings are produced by EfficientIP’s AI-driven DNS Threat Intelligence platform, which analyzes more than 150 billion DNS transactions daily, observes more than 500,000 newly observed domains each day and tracks 187 DGA families. Together, these signals provide the scale and context needed to identify patterns in emerging infrastructure without relying on any single indicator.

It combines linguistic, visual and behavioral analysis with graph theory to detect and connect activity across malware, phishing, DGA activity and emerging domain infrastructure.  The H1 2026 data reflects that breadth: 3.84 billion malware detections, nearly 69,000 devices per day on average generating non-resolving queries matching DGA families, and around 17 C&C domains associated with DGA families opening each day.

Dns Threat Intelligence Detection Using Linguistic Visual Behavioral and Graph Analysis with Multi source Intelligence Feeds

These signals become more valuable when detection leads to action. Within EfficientIP’s 360° DNS Security solution, DNS Threat Intelligence supports earlier investigation, while the DNS Threat Pulse feed brings domain intelligence into DNS filtering policies. Adaptive countermeasures automate a targeted response as the evidence strengthens, applying protection where it is needed without unnecessarily disrupting legitimate activity.

So, can DNS reveal signs of a malware threat before the broader attack becomes visible? The H1 2026 findings show that it can.

The breadcrumbs may already be there. The advantage comes from seeing them early enough to investigate and respond while the threat is still taking shape. 

Want to see where those breadcrumbs lead? Read the full H1 2026 DNS Threat Intelligence Report to explore the evidence behind the trends.

FAQ

Explore the Signals Behind the H1 2026 Threat Landscape

Follow the DNS breadcrumbs in EfficientIP’s H1 2026 DNS Threat Intelligence Report. Explore malware trends, emerging infrastructure signals, and five DGA family investigations to understand what deserves closer attention in your environment

Talk to an expert