Most malware came through HTTPS connections in Q1 2020

Signature-based antivirus protection would have been ineffective

Two-thirds of all malware-hit computers got infected through encrypted HTTPS connections in the first quarter of 2020.

That's accoring to WatchGuard, which also found that 72% of encrypted malware was categorized as zero-day, so signature-based antivirus protection would not have prevented their intrusion. The UK was the most targeted country for the five most widespread network attacks.

Companies that don’t conduct HTTPS inspection of encrypted traffic or engage in advanced behavior-based threat detection and response are not catching these types of threats. 

Advertisement - Article continues below

“Some organizations are reluctant to set up HTTPS inspection due to the extra work involved, but our threat data clearly shows that a majority of malware is delivered through encrypted connections and that letting traffic go uninspected is simply no longer an option,” said Corey Nachreiner, CTO, WatchGuard.

“As malware continues to become more advanced and evasive, the only reliable approach to defense is implementing a set of layered security services, including advanced threat detection methods and HTTPS inspection.”

Other findings for Q1 include:

  • Hosted or controlled Monero crypto miners made up half of the top 10 domains distributing malware. With crypto mining’s growth in popularity, online criminals have been adding crypto-mining modules to malware to take advantage of the opportunity.
  • Two of the top five malware variants include Flawed-Ammy and Cryxos. Flawed-Ammy remotely accesses victims’ computers through Ammyy Admin support software. The Cryxos Trojan, often used to target victims in Hong Kong, is typically attached as a fake invoice in an email and steals users’ email addresses and passwords.
  • A previously patched Adobe Acrobat Reader exploit from August 2017 made the top network attacks list in Q1, which shows the importance of staying on top of software patches and updates.
  • Three new domains involved in hosting phishing campaigns appeared on the top 10 list, including an impersonation of Mapp Engage (digital marketing and analytics), a Chinese campaign for Bet365 (online betting platform) and a now-defunct AT&T login page.
  • The increase in remote work due to COVID-19 has led to more attacks targeting individuals. There were also 11.6% fewer network attacks and 6.96 fewer malware hits, as there are fewer targets working within traditional networks.
Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now


Google Android

Over two dozen Android apps found stealing user data

7 Jul 2020

Best antivirus for Windows 10

30 Jun 2020
ethical hacking

Mobile banking apps are exposing user data to attackers

26 Jun 2020

Phishing attacks target unsuspecting Wells Fargo customers

24 Jun 2020

Most Popular

Business operations

Nvidia overtakes Intel as most valuable US chipmaker

9 Jul 2020

How to find RAM speed, size and type

24 Jun 2020

Is it time to put Intel Outside?

10 Jul 2020