ai-security EN

2026 64-Bits Malware Trend, (Mon, Feb 16th)

In 2022 (time flies!), I wrote a diary about the 32-bits VS. 64-bits malware landscape[ 1 ]. It demonstrated that, despite the growing number of 64-bits computers, the “old-architecture” remained the standard. In the SANS malware reversing training (FOR610[ 2 ]), we quickly cover the main differences between the two architectures. One of the conclusions is that 32-bits code is still popular because it acts like a comme denominator and allows threat actors to target more Windows computers. Yes, Microsoft Windows can smoothly execute 32-bits code on 64-bits computers. It is still the case in 2026? Did the situation evolved?

Last week, I make the exact same exercise and generated some statistics. I download the malware archive from Malware Bazaar[ 3 ] and re-executed my YARA rule.

Some basic numbers:

  • 2.167 ZIP archives (one per day)
  • 1.120.034.288.112 bytes  (1.1TB)
  • Time line covered: from 2020/02/24 - 2026/02/05
  • 346.985 samples analyzed (only PE files)
  • 312.307 32-bits samples
  • 34.677 64-bits samples
  • 11% of 64-bits samples

First, an overview of the global malware trend over the complete time period:

2026 64-Bits Malware Trend, (Mon, Feb 16th) illustration

Zoom on the last year:

2026 64-Bits Malware Trend, (Mon, Feb 16th) illustration

Now the interesting graph: the 64-bits sample trend over the complete period:

2026 64-Bits Malware Trend, (Mon, Feb 16th) illustration

Zoom on the last year:

2026 64-Bits Malware Trend, (Mon, Feb 16th) illustration

We can clearly see that, compared to 2022, there is now a trend in 64-bits code! Have a look at the last 30 days:

DateTotal Files32-bits64-bits
2026-01-07654124
2026-01-08694128
2026-01-091175760
2026-01-10442519
2026-01-11412516
2026-01-12604020
2026-01-13532825
2026-01-14634122
2026-01-15593623
2026-01-16322111
2026-01-1727189
2026-01-18653332
2026-01-19966036
2026-01-20714130
2026-01-21563323
2026-01-22823547
2026-01-23775225
2026-01-24501535
2026-01-25442816
2026-01-2612510223
2026-01-27906426
2026-01-28662937
2026-01-291215170
2026-01-30803941
2026-01-31682840
2026-02-01622735
2026-02-021297257
2026-02-031175364
2026-02-04844242
2026-02-0543739542

We are getting close to a 50-50 repartition!

???????

[1] https://isc.sans.edu/diary/32+or+64+bits+Malware/28968

[2] https://www.sans.org/cyber-security-courses/reverse-engineering-malware-malware-analysis-tools-techniques

[3] https://bazaar.abuse.ch

Xavier Mertens (@xme)

Xameco

Senior ISC Handler - Freelance Cyber Security Consultant

PGP Key