VIONIZ Threat Report
July 2026
A monthly summary of what VIONIZ devices detected and blocked around the world — powered entirely by our opt-in Crowd shield telemetry.
Data window: July 1 – July 31, 2026Top threats
Top threat families this month
| Family | Category | Blocks | Share of detections | Trend |
|---|---|---|---|---|
| Trojan.Downloader.Agent | Trojan | 3,841 | ▲ 21% | |
| PUA.Win32.Cracked | Potentially unwanted | 2,560 | ▲ 14% | |
| HackTool.Win32.Keygen | Hacktool | 2,118 | ▲ 12% | |
| Trojan.Script.Downloader | Trojan | 1,764 | ▲ 10% | |
| Ransom.Crypto.Mimic | Ransomware | 1,203 | ▼ 7% | |
| Worm.VBS.Autostart | Worm | 974 | ▼ 5% |
By platform
Detection breakdown
Windows
15,672 blocks · 86% of total
Cracked software and keygens remain the top initial-access vector. Ransomware detections rose 12% month-over-month.
macOS
2,532 blocks · 14% of total
Adware and fake-tool trojans dominate. We shipped 14 new YARA families for macOS this month.
Methodology
How this data is produced
All figures come from Crowd shield — the anonymous, hash-only telemetry VIONIZ devices opt into. No files, paths or personal data are involved. Detection quality is continuously validated in the VIONIZ benchmark laboratory, which measures real-world detection rate and false-positive rate against a curated, constantly refreshed corpus.
Family names reflect VIONIZ's in-house classification. Third-party naming may differ.