Most malware came through HTTPS connections in Q1 2020

Signature-based antivirus protection would have been ineffective

Two-thirds of all malware-hit computers got infected through encrypted HTTPS connections in the first quarter of 2020.

That's accoring to WatchGuard, which also found that 72% of encrypted malware was categorized as zero-day, so signature-based antivirus protection would not have prevented their intrusion. The UK was the most targeted country for the five most widespread network attacks.

Companies that don’t conduct HTTPS inspection of encrypted traffic or engage in advanced behavior-based threat detection and response are not catching these types of threats. 

“Some organizations are reluctant to set up HTTPS inspection due to the extra work involved, but our threat data clearly shows that a majority of malware is delivered through encrypted connections and that letting traffic go uninspected is simply no longer an option,” said Corey Nachreiner, CTO, WatchGuard.

“As malware continues to become more advanced and evasive, the only reliable approach to defense is implementing a set of layered security services, including advanced threat detection methods and HTTPS inspection.”

Other findings for Q1 include:

  • Hosted or controlled Monero crypto miners made up half of the top 10 domains distributing malware. With crypto mining’s growth in popularity, online criminals have been adding crypto-mining modules to malware to take advantage of the opportunity.
  • Two of the top five malware variants include Flawed-Ammy and Cryxos. Flawed-Ammy remotely accesses victims’ computers through Ammyy Admin support software. The Cryxos Trojan, often used to target victims in Hong Kong, is typically attached as a fake invoice in an email and steals users’ email addresses and passwords.
  • A previously patched Adobe Acrobat Reader exploit from August 2017 made the top network attacks list in Q1, which shows the importance of staying on top of software patches and updates.
  • Three new domains involved in hosting phishing campaigns appeared on the top 10 list, including an impersonation of Mapp Engage (digital marketing and analytics), a Chinese campaign for Bet365 (online betting platform) and a now-defunct AT&T login page.
  • The increase in remote work due to COVID-19 has led to more attacks targeting individuals. There were also 11.6% fewer network attacks and 6.96 fewer malware hits, as there are fewer targets working within traditional networks.
Featured Resources

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Simplify cluster security at scale

Centralised secrets management across hybrid, multi-cloud environments

Download now

The endpoint as a key element of your security infrastructure

Threats to endpoints in a world of remote working

Download now

2021 state of IT asset management report

The role of IT asset management for maximising technology investments

Download now

Recommended

Wisconsin Republican Party allegedly loses $2.3 million to hackers
hacking

Wisconsin Republican Party allegedly loses $2.3 million to hackers

30 Oct 2020
Bank-targeting malware disguises itself as video conferencing software
Security

Bank-targeting malware disguises itself as video conferencing software

19 Oct 2020
What is hacktivism?
hacking

What is hacktivism?

13 Oct 2020
Microsoft: Iranian hackers are exploiting ZeroLogon flaw
Security

Microsoft: Iranian hackers are exploiting ZeroLogon flaw

6 Oct 2020

Most Popular

Do smart devices make us less intelligent?
artificial intelligence (AI)

Do smart devices make us less intelligent?

19 Oct 2020
Best MDM solutions 2020
mobile device management (MDM)

Best MDM solutions 2020

21 Oct 2020
What is Neuralink?
Technology

What is Neuralink?

24 Oct 2020