Trends H1 2026: Cyber Insights
Introduction
To protect our users, Quad9 blocks DNS lookups of malicious host names from an up-to-the-minute list of threats. This blocking action protects your computer, mobile device, or IoT systems against a wide range of threats, such as malware, phishing, spyware, and botnets, and it can improve performance and privacy. This blogpost provides security insights on the threats blocked by Quad9 DNS between January and June 2026. This time we analyzed the top 50 domains blocked by us, which together accounted for more than 14 billion blocked DNS queries in six months. The report combines DNS telemetry data and open-source intelligence with statistics and analysis to provide security insights on the top malicious domains visited by our users and blocked by Quad9 DNS.
To better understand the nature of the high-volume threats targeting our Quad9 users, we categorized the top 50 blocked domains by their primary intent. The following chart illustrates the distribution of these threats, revealing a continued concentration in CrowdStrike-mimicking domains – still the largest cluster nearly two years after the 2024 Falcon outage – alongside newly dominant Android TV botnet command-and-control traffic and persistent push-notification scam and malvertising infrastructures. New in this edition, we additionally analyze the most blocked and abused top-level domains (TLDs), taking a closer look at where malicious domains live.

A note on methodology: the figures in this report count blocked DNS lookups, not infected devices - a single compromised device can generate millions of queries, and caching and retry behavior differ per domain. Likewise, the geographic breakdowns reflect where Quad9’s users are located as well as where victims are concentrated. All figures cover 1 January through 30 June 2026.
Android TV Botnets: Compromised Set-Top Boxes Likely Behind Our Most-Blocked Domain
The single most-queried domain blocked by Quad9 in H1 2026 received more than 1.1 billion DNS queries in six months. Its host name follows the pattern of a domain generation algorithm (DGA): a disposable, randomized label that carries no meaning to a human reader but allows malware to reliably locate its command-and-control (C2) infrastructure while evading simple blocklists. Five further domains in our top 50 share the same fingerprint, and together this cluster generated close to 2.2 billion blocked queries. The monthly timeline below shows how the threat evolved: activity was heavily front-loaded, with the DGA cluster peaking above 930 million queries in January before collapsing to under 25 million by June - a decline of more than 97% - while traffic to the two confirmed TV-box C2 domains only became visible in February and, after a dip in March, climbed to their peak by the end of the period. Such rotation of C2 infrastructure mid-campaign is exactly the behavior DGAs are designed to enable.

A per-domain view makes the rotation explicit. One DGA domain was queried almost exclusively in January before going dark; a second was abandoned at the end of February; a third ramped up sharply in February, peaking at 176 million queries, and was discarded by April; and the cluster’s primary domain went down steadily from 392 million queries in January to 15 million in June. Meanwhile, two smaller domains remained at a constant 20-30 million queries per month until one of them vanished in June, and the two confirmed TV-box C2 domains - absent in January - grew to a combined 98 million queries per month by the end of the period. This burn-and-rotate tactic, with fresh infrastructure activated as old host names are retired, is the clearest evidence that the cluster is centrally operated.

While this cluster has not yet been publicly attributed to a named malware family, its structure and traffic profile are consistent with the botnets that plague low-cost Android TV boxes, such as Vo1d and BADBOX, which security researchers estimate have controlled well over a million devices worldwide. Two other domains in our top 50 make the Android TV connection explicit: with roughly 330 million queries between them, both are confirmed C2 and click-fraud domains of the malware found pre-installed on T95 and similar Android TV boxes sold through mainstream online marketplaces. These devices arrive from the factory already compromised, silently generating ad-fraud traffic and offering attackers a foothold inside home networks - a reminder that supply-chain security failures increasingly reach consumers directly. Notably, the Mirai botnet C2 domain that topped our H2 2025 report dropped out of the top 50 entirely in H1 2026.
Geographically, this threat has a clear center of gravity: eight of the ten largest source countries are in Latin America, with Venezuela and Colombia alone accounting for nearly one billion blocked queries - consistent with the strong presence of low-cost, pre-compromised Android TV boxes in the region.

Impersonation Risks: A Fake Meta-Support Domain Persists
Beyond high-volume botnet activity, we continue to observe significant traffic directed toward a domain that masquerades as an official support channel for Meta Verified services. In H1 2026, we blocked more than 146 million queries to this domain - a notable decline from the 224 million queries observed in H2 2025, but still enough to keep it among our top 50 blocked domains a year after we first reported on it. Our analysis confirms that this is a fraudulent domain used primarily for email forwarding in phishing and spam campaigns. Its support-channel-style naming is designed to exploit users seeking account verification or assistance.

The geographic pattern is unchanged from H2 2025: Türkiye and Brazil remain the two largest sources of blocked queries to this domain, followed by South Africa and Indonesia.

Threat Actors Still Exploiting the CrowdStrike Incident
In July 2024, a faulty update to CrowdStrike’s Falcon Sensor security software caused widespread disruption across global IT systems. This incident resulted in millions of Windows computers crashing, severely impacting critical services in various sectors, including air travel, banking, and healthcare. After the incident, CrowdStrike Intelligence has observed threat actors exploiting the Falcon Sensor incident. These actors are engaging in various malicious activities, including:
- Phishing emails: Disguised as legitimate support communications from CrowdStrike.
- Impersonation: Posing as CrowdStrike staff during phone calls.
- False research claims: Presenting themselves as independent researchers, falsely linking the technical issue to a cyberattack and offering remediation guidance.
- Malicious scripts: Selling scripts that allegedly automate recovery from the content update issue, likely containing malicious code.
Quad9 continues to block domains abused by those threat actors. In total, in H1 2026, we observed more than 4.6 billion DNS queries to 13 such domains - up from 3.9 billion queries to 12 domains in H2 2025. Nearly two years after the incident, opportunistic campaigns built around the CrowdStrike brand remain the single largest threat cluster in our data. The domains are typosquats combining the CrowdStrike or Falcon brand with outage-related keywords such as “down”, “bluescreen”, “token”, “helpdesk” and “fix”. Eleven of the thirteen each attracted roughly 400 million queries over the period - a remarkably uniform volume that suggests coordinated, automated infrastructure rather than organic victim traffic.
Push-Notification Scams and Malvertising: A Persistent Top Threat
Malvertising remains a regular part of our most-blocked list, though the leading infrastructure has shifted since our last report. In H1 2026, browser push-notification scam networks dominated this category: the largest domain, themed as a fake “new message” alert, alone drew more than 800 million queries, with two sibling push-scam domains (358 million and 128 million queries) following the same playbook. These sites trick users into accepting browser notifications - typically via fake “you have a new message” prompts or fake video players - and then flood victims with fraudulent ads, scareware, and malware download links long after they have left the original page. Related ad-fraud infrastructure rounds out the cluster: an ad “partner” endpoint (338 million queries), a fake video-player script host (89 million), and an ad-network script domain widely abused in malvertising campaigns (88 million). In total, this ecosystem accounted for roughly 1.8 billion blocked queries in H1 2026.

The push-scam ecosystem is a distinctly global problem, led by Bangladesh, Russia, and South Africa - markets where inexpensive Android devices and aggressive ad-driven content ecosystems overlap.

Cryptojacking: 688 Million Queries to Monero Mining Pools
Four domains in our top 50 belong to public Monero cryptocurrency mining pools: the busiest received 298 million queries in six months, and the four together 688 million. While mining pools are legitimate services, DNS traffic to them at this volume through a security resolver overwhelmingly reflects cryptojacking: miners installed by malware on compromised computers and servers, quietly consuming their victims’ electricity and computing power for someone else’s profit. One of the four host names carries the name of XMRig, the open-source miner most commonly bundled with such malware.

The origin countries for mining-pool traffic skew toward Russia, Germany, the United States, Brazil, and France - several of them major server-hosting markets, consistent with cryptojacking of compromised servers as much as of personal computers.

Other Notable Threats in the Top 50
Several further threat categories appear in this half-year’s top 50 blocked domains:
- Supply-chain attack: the domain at the center of the June 2024 polyfill supply-chain attack (91 million queries) remains blocked ecosystem-wide, after its new owner began injecting malicious JavaScript into a library previously embedded on more than 100,000 websites.
- Proxyware: an API endpoint of a commercial residential proxy service (77 million queries) that positioned itself as the successor to the FBI-dismantled 911 S5 botnet. Traffic to this endpoint typically originates from proxyware silently installed on victims’ machines, renting out their internet connections for abuse by third parties.
- Malware support infrastructure: a public IP-geolocation API (109 million queries) heavily abused by infostealers and loaders to profile freshly infected victims before deploying further payloads.
- Stalkerware: two API endpoints of a popular child-tracking application (251 million queries combined) classified by several threat feeds as stalkerware - illustrating the grey zone between parental control and surveillance.
- Unattributed high-volume infrastructure: the second most-queried domain in our top 50, 103.chtsite[.]com (over 1 billion queries in six months), remains unattributed at the time of writing. Sustained volume of this scale on a single host is itself a signal, and we continue to monitor the domain; threat intelligence partners with visibility into it are welcome to reach out.
Abused TLDs: Where Malicious Domains Live
Zooming out from individual domains to the top-level domains (TLDs) they live in reveals two very different abuse patterns. Note that these figures cover all queries blocked by Quad9 in H1 2026, not just the top 50 domains. By raw volume, .com unsurprisingly leads with 33.9 billion blocked queries to 148 million unique blocked domains - a reflection of the TLD’s sheer size rather than lax registration policies. It is followed by .ru (2.1 billion blocked queries), .biz (1.4 billion), .org and .net (1.4 and 1.3 billion), with inexpensive newer gTLDs such as .site, .xyz, and .top close behind.

The more interesting signal, however, is the ratio of queries to unique domains. .su - the legacy country-code TLD of the Soviet Union, still operating 35 years after the state it was assigned to ceased to exist - hosted 195 million unique blocked domains, more than .com itself, yet drew only 576 million queries: barely three queries per domain. This burn-and-discard pattern is the signature of domain generation algorithms, with botnets churning through enormous numbers of short-lived host names to stay ahead of blocklists. At the opposite extreme, .ax - the tiny country-code TLD of the Åland Islands - attracted 514 million queries to just 113 blocked domains - roughly 4.5 million queries per domain - driven by a handful of high-traffic torrent-tracker hosts. The .stream TLD shows the same concentration: 213 million queries to some 1,600 domains, dominated by the cryptomining pools described earlier. In between sit the familiar inexpensive gTLDs - .top, .xyz, .cc, .site, .cyou, and .shop - each contributing well over a million unique blocked domains, a reminder that low registration prices reliably attract abuse at scale.
Conclusions
The first half of 2026 showed both how quickly criminal infrastructure changes and how stubbornly it persists. In six months, an Android TV botnet burned through half a dozen machine-generated C2 domains, rotating to fresh infrastructure as fast as the old names were identified - while at the other extreme, threat actors are still profitably exploiting a software outage from July 2024, with CrowdStrike-themed domains once again our largest blocked cluster. The abuse economy also has a clear geography: pre-compromised TV boxes concentrated in Latin America, push-notification scams across emerging markets, cryptojacking following server-hosting footprints, and a Soviet-era top-level domain serving as a disposable-domain factory. Blocking at the DNS layer remains one of the few defenses that keep pace with this rate of change.
Over the years, it’s become easier and cheaper for cybercriminals to attack internet users. Quad9’s mission is to improve the security and stability of the Internet and reduce users’ vulnerability to risk and become more effective in their daily online interactions - even in the face of growing cyber attacks.
By preventing connections to malicious sites, Quad9 eliminates exposure to risks before they are downloaded to computers or a victim can see the fraudulent website. The inability to reach a malicious host means that defenses such as virus protection or user-based detection such as certificate examination are never called into action.
As a DNS provider, Quad9 has the unique opportunity to analyze the volumes and trends of malware campaigns. If you are a security researcher or threat intelligence provider and want to hear more, contact us via our website at: https://quad9.net/support/contact
About Quad9
Quad9, a nonprofit in the US and Switzerland, provides free cybersecurity services to the emerging world via secure and private DNS lookup. Quad9 operates approximately 200 locations across ~ 100 nations, blocking hundreds of millions of malware, phishing, and spyware events daily for millions of end users. Quad9 reduces harm in vulnerable regions, increases privacy against criminal or institutionalised interception of internet data, and improves performance in under-served areas.
____________________________________________________________________
References:
https://blogs.infoblox.com/threat-intelligence/pushed-down-the-rabbit-hole/
https://www.securityweek.com/vo1d-botnet-evolves-as-it-ensnares-1-6-million-android-tv-boxes/
https://github.com/DesktopECHO/T95-H616-Malware
https://github.com/cyb3rmik3/Hunting-Lists/blob/main/crowdstrike-phishing-domains.csv