IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Most malware came through HTTPS connections in Q1 2020

Signature-based antivirus protection would have been ineffective

Two-thirds of all malware-hit computers got infected through encrypted HTTPS connections in the first quarter of 2020.

That's accoring to WatchGuard, which also found that 72% of encrypted malware was categorized as zero-day, so signature-based antivirus protection would not have prevented their intrusion. The UK was the most targeted country for the five most widespread network attacks.

Companies that don’t conduct HTTPS inspection of encrypted traffic or engage in advanced behavior-based threat detection and response are not catching these types of threats. 

“Some organizations are reluctant to set up HTTPS inspection due to the extra work involved, but our threat data clearly shows that a majority of malware is delivered through encrypted connections and that letting traffic go uninspected is simply no longer an option,” said Corey Nachreiner, CTO, WatchGuard.

“As malware continues to become more advanced and evasive, the only reliable approach to defense is implementing a set of layered security services, including advanced threat detection methods and HTTPS inspection.”

Other findings for Q1 include:

  • Hosted or controlled Monero crypto miners made up half of the top 10 domains distributing malware. With crypto mining’s growth in popularity, online criminals have been adding crypto-mining modules to malware to take advantage of the opportunity.
  • Two of the top five malware variants include Flawed-Ammy and Cryxos. Flawed-Ammy remotely accesses victims’ computers through Ammyy Admin support software. The Cryxos Trojan, often used to target victims in Hong Kong, is typically attached as a fake invoice in an email and steals users’ email addresses and passwords.
  • A previously patched Adobe Acrobat Reader exploit from August 2017 made the top network attacks list in Q1, which shows the importance of staying on top of software patches and updates.
  • Three new domains involved in hosting phishing campaigns appeared on the top 10 list, including an impersonation of Mapp Engage (digital marketing and analytics), a Chinese campaign for Bet365 (online betting platform) and a now-defunct AT&T login page.
  • The increase in remote work due to COVID-19 has led to more attacks targeting individuals. There were also 11.6% fewer network attacks and 6.96 fewer malware hits, as there are fewer targets working within traditional networks.
Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Recommended

Twilio account breach result of sophisticated social engineering campaign
Security

Twilio account breach result of sophisticated social engineering campaign

9 Aug 2022
Over 200,000 DrayTek routers vulnerable to total device takeover
Security

Over 200,000 DrayTek routers vulnerable to total device takeover

3 Aug 2022
Data on 69 million Neopets users stolen and listed for sale on hacker forum
Security

Data on 69 million Neopets users stolen and listed for sale on hacker forum

21 Jul 2022
HackerOne employee fired for using position to steal bug bounties
Security

HackerOne employee fired for using position to steal bug bounties

4 Jul 2022

Most Popular

Cyber attack on software supplier causes "major outage" across the NHS
cyber attacks

Cyber attack on software supplier causes "major outage" across the NHS

8 Aug 2022
Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022