It's not necessarily about the number of viruses. The bigger change is that traditional “viruses” are now only one part of a much larger malware ecosystem. Ransomware, information-stealing malware, remote-access trojans, botnets, banking malware and malware delivered through phishing or compromised software are much more significant threats than classic self-replicating viruses. The overall volume of malicious activity remains extremely high, with attackers constantly creating new variants to evade security products.
A large amount of malware originates from organized cybercrime groups operating internationally. Major sources include Russia and other parts of Eastern Europe, China, North Korea, Iran and criminal groups distributed across many countries, although malware infrastructure can be located almost anywhere. Attackers commonly use compromised servers, rented cloud infrastructure, bulletproof hosting and cryptocurrency services, making the physical location of the criminals difficult to determine. It is also common for one criminal group to purchase access to a victim network from another criminal group rather than carrying out the initial intrusion itself.
AI is making this ecosystem more dangerous, but it has not fundamentally changed how malware works. Criminals can use generative AI to create or modify malicious code, troubleshoot malware, generate phishing messages in better English and other languages, automate reconnaissance and develop convincing social-engineering campaigns. AI also makes it easier for less-skilled criminals to perform activities that previously required significant technical knowledge. At the same time, defenders use AI to detect abnormal behavior, identify malware variants and analyze enormous quantities of security telemetry, so AI is being used on both sides.
The people behind malware can be prosecuted when investigators can identify them and obtain sufficient evidence. There have been numerous arrests, indictments, convictions and prison sentences involving ransomware operators, botnet operators, malware developers and other cybercriminals. For example, U.S. and international authorities have prosecuted members of ransomware groups, dismantled botnets and seized criminal infrastructure. Cryptocurrency transactions, server records, malware infrastructure, communications, seized computers and mistakes made by criminals can all help investigators establish attribution.
The biggest problem is jurisdiction. If someone attacks U.S. organizations from a country that will not cooperate with U.S. law enforcement, identifying the person does not necessarily mean they can be arrested. Investigators may know exactly who is responsible but be unable to physically reach them. Arrests often occur when criminals travel to a cooperating country, when another country agrees to extradite them, or when international law-enforcement operations identify and apprehend multiple members simultaneously.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin