Most malware came through HTTPS connections in Q1 2020

Signature-based antivirus protection would have been ineffective

Two-thirds of all malware-hit computers got infected through encrypted HTTPS connections in the first quarter of 2020.

That's accoring to WatchGuard, which also found that 72% of encrypted malware was categorized as zero-day, so signature-based antivirus protection would not have prevented their intrusion. The UK was the most targeted country for the five most widespread network attacks.

Companies that don’t conduct HTTPS inspection of encrypted traffic or engage in advanced behavior-based threat detection and response are not catching these types of threats. 

“Some organizations are reluctant to set up HTTPS inspection due to the extra work involved, but our threat data clearly shows that a majority of malware is delivered through encrypted connections and that letting traffic go uninspected is simply no longer an option,” said Corey Nachreiner, CTO, WatchGuard.

“As malware continues to become more advanced and evasive, the only reliable approach to defense is implementing a set of layered security services, including advanced threat detection methods and HTTPS inspection.”

Other findings for Q1 include:

  • Hosted or controlled Monero crypto miners made up half of the top 10 domains distributing malware. With crypto mining’s growth in popularity, online criminals have been adding crypto-mining modules to malware to take advantage of the opportunity.
  • Two of the top five malware variants include Flawed-Ammy and Cryxos. Flawed-Ammy remotely accesses victims’ computers through Ammyy Admin support software. The Cryxos Trojan, often used to target victims in Hong Kong, is typically attached as a fake invoice in an email and steals users’ email addresses and passwords.
  • A previously patched Adobe Acrobat Reader exploit from August 2017 made the top network attacks list in Q1, which shows the importance of staying on top of software patches and updates.
  • Three new domains involved in hosting phishing campaigns appeared on the top 10 list, including an impersonation of Mapp Engage (digital marketing and analytics), a Chinese campaign for Bet365 (online betting platform) and a now-defunct AT&T login page.
  • The increase in remote work due to COVID-19 has led to more attacks targeting individuals. There were also 11.6% fewer network attacks and 6.96 fewer malware hits, as there are fewer targets working within traditional networks.
Featured Resources

Unlocking collaboration: Making software work better together

How to improve collaboration and agility with the right tech

Download now

Four steps to field service excellence

How to thrive in the experience economy

Download now

Six things a developer should know about Postgres

Why enterprises are choosing PostgreSQL

Download now

The path to CX excellence for B2B services

The four stages to thrive in the experience economy

Download now

Recommended

HackBoss malware is using Telegram to steal cryptocurrency from other hackers
cryptocurrencies

HackBoss malware is using Telegram to steal cryptocurrency from other hackers

16 Apr 2021
Russia launched over a million cyber attacks in three months
hacking

Russia launched over a million cyber attacks in three months

13 Apr 2021
Hackers leak data from dark web marketplace
cyber security

Hackers leak data from dark web marketplace

9 Apr 2021

Most Popular

Microsoft is submerging servers in boiling liquid to prevent Teams outages
data centres

Microsoft is submerging servers in boiling liquid to prevent Teams outages

7 Apr 2021
University of Hertfordshire's entire IT system offline after cyber attack
cyber attacks

University of Hertfordshire's entire IT system offline after cyber attack

15 Apr 2021
NSA uncovers new "critical" flaws in Microsoft Exchange Server
servers

NSA uncovers new "critical" flaws in Microsoft Exchange Server

14 Apr 2021