In short: Positive Technologies analysed pilot deployments of its PT NAD network threat detection system across Russian and CIS companies for the second half of 2025 and first half of 2026. Malware was active in 70% of organisations — up from 46% in the previous study. The key infection vector: employees' personal laptops used for remote work, connected to the corporate network.
What Positive Technologies researchers found
On September 9, 2026, Positive Technologies published findings from its large-scale analysis of PT NAD pilot projects across Russian and CIS organisations. The conclusion is sobering: malware was detected in 70% of companies participating in pilots, up from 46% in the prior study, as reported by Rambler/Tech and Kommersant.
A companion Positive Technologies report covering H1 2026 found that malware was used in 65% of successful cyberattacks against Russian companies — meaning malicious code played a decisive role in two out of every three successful breaches. Read more about current cybersecurity threats on our digital security blog.
The threat landscape: proxies, miners, and spyware
The study identified three dominant malware categories in Russian and CIS corporate networks.
Residential proxies — 67% of companies. The most widespread threat. A residential proxy turns an infected device into a node in an anonymisation network: third-party traffic is routed through it as if from a regular home IP address. The most common program — Infatica — was found in 62% of organisations. It is typically installed silently through free browser extensions or third-party apps. The device appears to work normally, but your IP address ends up in the logs of whatever traffic flows through it — including potentially illegal activity.
Cryptocurrency miners — 54% of companies. Hidden Monero mining programs were found in more than half of the studied organisations (a specific miner variant in 47%). A miner silently consumes computing resources. It does not steal credentials directly — but the vulnerability it exploited to get in remains open to more dangerous threats as well.
Remote Access Trojans (RAT) — 22% of companies. RATs give attackers full control of the infected device: logging keystrokes, capturing the screen, running files and exfiltrating documents. A RAT in a corporate network means full compromise: the attacker sees everything the user sees and can act in their name across any corporate system.
Spyware — 6% of companies. Though the share is smaller, spyware causes disproportionate damage: it systematically collects sensitive data — credentials, correspondence, corporate documents — and sends it to its operators. Its presence typically signals a prolonged, targeted intrusion rather than an opportunistic infection.
How personal laptops open the door to corporate infrastructure
Positive Technologies experts highlight a concerning infection vector: employees' personal mobile devices and home laptops used for remote work. When a staff member connects to corporate infrastructure from a personal device that already runs a miner or residential proxy, the boundary between home and office network effectively disappears.
Weak network configuration compounds the risk. The study revealed critical misconfigurations across the surveyed organisations:
- 87% of companies use insecure protocols that transmit credentials in plain text
- 74% of organisations run third-party remote access software without adequate oversight
- 61% of networks have dictionary passwords — trivially crackable by brute force in minutes
The combination means an attacker needs only to infect one employee's personal laptop — and from there, exploiting weak passwords and unencrypted protocols, can move deep into corporate infrastructure without ever attacking the perimeter directly.
What this means for individual users
Affected organisations are not limited to large enterprises. For an ordinary employee or freelancer working from home, the risk is immediate and personal.
Personal accounts may be at risk. If a RAT or spyware is active on a work device — or on a colleague's device in the same network — not just work accounts but personal ones (email, messaging apps, online banking) can be intercepted.
A residential proxy on your device is a legal liability. If your IP is used for someone else's traffic, it is your address that appears in provider logs and potentially in law enforcement records. Most victims of this type of infection have no idea their device is acting as an anonymisation gateway.
A "harmless" miner is not harmless. A hidden miner does not steal passwords, but it drains your battery, overheats your device, and shortens its lifespan. The vulnerability it exploited to get in remains available to more dangerous payloads.
How to protect your device and data
Positive Technologies research shows that monitoring network traffic is the most reliable way to detect malware activity. At the individual level, these steps meaningfully reduce exposure.
Separate personal and work devices. The less personal browsing and downloading happens through a work connection, the lower the risk of accidental infection via a downloaded file or browser extension.
Update software immediately. Most infections found by PT NAD exploited long-patched vulnerabilities in outdated systems. An up-to-date OS, browser and office suite eliminates entire classes of attack vectors.
Replace dictionary passwords and enable 2FA. 61% of corporate networks are vulnerable because of weak passwords alone. A unique, long password plus two-factor authentication blocks most credential attacks.
Encrypt your network traffic, especially on untrusted connections. LiMP VPN for iOS and Android encrypts all outgoing traffic: your ISP and any Wi-Fi router — including one compromised by a residential proxy — cannot see your data in plain text. To be clear: a VPN secures network traffic, not the device itself — antivirus and system updates remain essential. But combined with an updated OS and strong passwords, an encrypted tunnel closes one more channel through which your data could leak. LiMP VPN plans start from $0.99/month.
