Skip to content
All publications
2026-VSPAM-006July 12, 2026

Trends in Spam, Phishing, Spoofing, Malware & DNS Abuse

By vSpam.org Independent Research, vSpam Researcher Team

Abstract

June 2026 monthly research brief, focused on disruption. Operation Endgame removed 326 servers and 142 domains supporting SocGholish, Amadey and StealC, recovering 27 million stolen credentials, while Europol dismantled a laundering service that had washed €336M since 2021. Ransomware nevertheless rose 9.4%, leadership changed hands after five months, and an unseen group debuted at number two. The issue examines what disruption actually buys.

Key Findings

  1. 1Operation Endgame seized 326 servers and 142 domains, recovered ~27 million credentials and restrained €41M in criminal assets
  2. 2Ransomware rose 9.4% to 707 victims across 63 groups; TheGentlemen displaced Qilin after its five-month run, and DeadLock debuted directly at second place with 81
  3. 3Spamhaus recorded botnet C&C servers down 30% to 14,952, with Sliver overtaking Cobalt Strike as detections for the latter fell 68%
  4. 4One registrar cut abused registrations 90% in six months while another rose 901% — registrar abuse volume is a policy variable, not a constant
  5. 5vSpam.org corpus recorded a 5,059-indicator single-month loader burst and the complete reversion of May's novelty-gTLD concentration

Topics

monthly-briefoperation-endgameransomwarebotnet-c2dns-abuselaw-enforcement

Cite this report

vspam.org Research Team. "Trends in Spam, Phishing, Spoofing, Malware & DNS Abuse." 2026-VSPAM-006, vspam.org, July 12, 2026. https://vspam.org/research/trends-spam-phishing-spoofing-malware-dns-abuse-june-2026

Licensed under CC BY 4.0. You may share and adapt this work with attribution.