Hypervisors went from 3% of malicious encryption events in the first half of 2025 to 25% in the second half, per Huntress. Windows still absorbed 87.4% of desktop malware detections the same year. This post breaks down verified 2024 and 2025 figures on ransomware attacks by operating system across Windows, Linux, VMware ESXi, and macOS.

Ransomware Attacks by Operating System: Key Notes

  • Windows recorded 419,000 malware detections in 2025, nearly seven times the 60,000 logged on macOS, per Surfshark.
  • Hypervisor encryption events grew eightfold across 2025, from 3% to 25% of the total, per Huntress.
  • Exposed VMware ESXi servers fell 90%, from 85,000 in February 2023 to about 8,900 in 2024, per Forescout.
  • 22 new macOS malware families appeared in 2024, including the NotLockBit ransomware, per SecurityWeek.
  • Comparitech tracked 7,419 ransomware attacks worldwide in 2025, up 32% from 5,631 in 2024.

The short version of ransomware attacks by operating system: Windows takes the raw volume, Linux hosts the highest-value single targets through ESXi, and macOS ransomware exists but stays under 5% of Mac threats. Exploited vulnerabilities were the top entry point in 2025 at 32% of incidents, per Sophos.

Which Operating System Faces the Most Ransomware Attacks?

Windows. Surfshark Antivirus logged 419,000 malware detections on Windows in 2025 against 60,000 on macOS, a split of 87.4% to 12.6%.

The gap tracks market position. Windows held about 71% of the desktop market in 2025, macOS about 15%.

Desktop OSMalware detections (2025)Share
Windows419,00087.4%
macOS60,00012.6%

Source: Surfshark

PowerShell script malware led the Windows categories at 22% of identified threats in 2025, based on Surfshark data. Detections spiked in July, when attackers used PowerShell to drop web shells and load ransomware through SharePoint remote-code-execution flaws.

Attackers reuse the same encryptors against the largest available pool of targets. The pattern holds even as Linux desktop share passes 5% in the US.

Linux and ESXi Ransomware Attacks by Operating System

Linux made up about 9% of endpoint malware signature events in Elastic’s mid-2024 to mid-2025 telemetry. Of the malicious behaviors Elastic logged on Linux, 89% were brute-force attempts, most against public-facing SSH.

Raw counts understate the exposure. Linux runs most web servers, cloud workloads, and the VMware ESXi hypervisors that hold virtual machines in bulk, a picture covered in detail in our Linux malware and vulnerability statistics.

Linux / ESXi indicatorValueSource
Exposed ESXi servers, Feb 202385,000Forescout
Exposed ESXi servers, 2024~8,900Forescout
Average ESXi ransom demand, 2024$5MThe Hacker News
Hypervisor share of encryption events, H1 20253%Huntress
Hypervisor share of encryption events, H2 202525%Huntress

Source: Forescout; The Hacker News; Huntress

Exposed hosts dropped 90% year over year, yet the hypervisor share of encryption events climbed eightfold across 2025. Attackers moved from scanning the open internet to targeted intrusions that reach ESXi through Active Directory, which is one reason enterprises keep tightening controls tracked in our SELinux and AppArmor enforcement data.

The CVE-2024-37085 authentication bypass let Akira and Black Basta re-create a deleted “ESX Admins” group and take full host control, per The Hacker News. CISA confirmed in October 2025 that ransomware campaigns were exploiting the Linux kernel flaw CVE-2024-1086.

Qilin and Cross-Platform Encryptors

Qilin, also tracked as Agenda, hit more than 700 victims across 62 countries from January 2025 onward, per Trend Micro. It sometimes ran its Linux encryptor on Windows machines to slip past endpoint tools.

Encryptors written in Rust and Go make that portability cheap, a shift visible in our 2026 programming language rankings and the Rust adoption figures behind them.

macOS Ransomware Attacks: How Real Is the Threat?

Still small, no longer theoretical. Security researcher Patrick Wardle counted 22 new macOS malware families in 2024, per SecurityWeek.

The standout is NotLockBit. It encrypts files and exfiltrates data to attacker-controlled AWS storage for double extortion, though no confirmed in-the-wild victims have been recorded yet.

macOS ransomware indicatorValueSource
New macOS malware families, 202422SecurityWeek
Ransomware share of macOS threatsBelow 5%TechLila
macOS ransomware growth, 2024 to 2025Over 20%TechLila
Average enterprise Mac ransom demandOver $50,000TechLila

Source: SecurityWeek; TechLila

Infostealers and adware still define the Mac threat mix. Surfshark’s 2025 breakdown put viruses at 28% of macOS detections, trojans at 26%, riskware at 15%, adware at 8%, and exploits at 7%.

NotLockBit targets Apple Silicon and works around the Transparency, Consent, and Control framework by pushing users to click through permission prompts, per SecurityWeek. The 20%-plus rise into 2025 shows attackers testing whether double extortion pays on Apple hardware.

How Does Ransomware Get Into Each Operating System?

Entry routes differ by platform. Sophos ranked exploited vulnerabilities as the top root cause of 2025 incidents for the third year running.

Initial access vectorShare of 2025 attacks
Exploited vulnerabilities32%
Compromised credentials23%
Malicious email19%
Phishing18%

Source: Sophos

Vulnerability exploitation maps to how Linux and ESXi get hit through unpatched public-facing services. Credential theft and email lures skew toward Windows-heavy user environments.

Credential-based entry fell from 29% in 2024 to 23% in 2025, a drop Sophos ties in part to faster defender response. On the Linux side, most brute-force pressure lands on SSH, the busiest tool in our Linux command usage data.

Ransomware Attack Volume and Payments, 2024 to 2025

Attack counts rose while paid ransoms fell. Comparitech tracked 7,419 ransomware attacks worldwide in 2025, up 32% from 5,631 in 2024.

Metric20242025Source
Tracked ransomware attacks worldwide5,6317,419Comparitech
Median ransom payment$2.0M$1.0MSophos
Victims recovering within one week35%53%Sophos

Source: Comparitech; Sophos

The median payment halved to $1 million while week-one recovery rose to 53%, per Sophos. More organizations are refusing to pay and restoring faster.

Chainalysis tracked roughly $820 million in on-chain ransom payments for 2025, down 8% from 2024, with a record-low pay rate near 28% of victims. The pattern holds across operating systems: more campaigns, less money per victim.

FAQs

Which operating system faces the most ransomware attacks?

Windows. It accounted for 87.4% of desktop malware detections in 2025, nearly seven times the macOS figure, driven by its roughly 71% desktop market share, per Surfshark.

Are Linux systems safe from ransomware?

No. Linux was about 9% of endpoint malware events in Elastic’s telemetry, but it hosts the VMware ESXi hypervisors behind the fastest-growing ransomware category, up from 3% to 25% of encryption events in 2025.

How much do ESXi ransomware demands cost?

Average ransom demands against VMware ESXi servers reached $5 million in 2024, reflecting the leverage of encrypting many virtual machines from one host, per The Hacker News.

Is macOS ransomware a real threat in 2025?

Small but growing. Ransomware sits below 5% of macOS threats, though 22 new Mac malware families appeared in 2024 and ransomware activity rose more than 20% into 2025.

What is the most common way ransomware gets in?

Exploited vulnerabilities, at 32% of 2025 attacks, followed by compromised credentials at 23%, malicious email at 19%, and phishing at 18%, per Sophos.

Sources

https://surfshark.com/research/chart/malware-cases-windows-macOS
https://www.sophos.com/en-us/content/state-of-ransomware
https://www.comparitech.com/ransomware-attack-map/
https://www.elastic.co/security-labs

Willie has over 15 years of experience in Linux system administration and DevOps. After managing infrastructure for startups and enterprises alike, he founded Command Linux to share the practical knowledge he wished he had when starting out. He oversees content strategy and contributes guides on server management, automation, and security.