ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

UPDATE -- WatchGuard Threat Lab Reports 40% Jump in Evasive Malware over Encrypted Connections as Cybercriminals Embrace Stealthy Tactics

SEATTLE, Oct. 21, 2025 (GLOBE NEWSWIRE) -- WatchGuard® Technologies, a global leader in unified cybersecurity for managed service providers (MSPs), today released the findings of its latest Internet Security Report, a quarterly analysis detailing the top malware, network, and endpoint security threats observed by the WatchGuard Threat Lab researchers during April through June, the second quarter of 2025.  

The report’s key findings reveal a 40% (quarter-over-quarter) increase in evasive, advanced malware. The data highlights encrypted channels as adversaries favored attack vector using Transport Layer Security (TLS), the encryption protocol behind most secure web traffic. While TLS is vital for protecting users, attackers increasingly exploit it to disguise malicious payloads.  

Overall malware detections rose 15% in Q2, driven by an 85% increase from Gateway AntiVirus (GAV) and a 10% gain from IntelligentAV (IAV), underscoring IAV’s growing role in catching sophisticated threats. With 70% of all malware now delivered via encrypted connections, the findings highlight attackers’ increasing reliance on obfuscation and stealth, and the need for organizations to improve visibility into encrypted traffic and adopt flexible protection strategies. 

The Threat Lab also observed a slight rise in network attacks, increasing by 8.3%. At the same time, the diversity of attacks narrowed, with 380 unique signatures triggered compared to 412 last quarter. Notably, a brand-new malicious JavaScript detection, “WEB-CLIENT JavaScript Obfuscation in Exploit Kits,” entered the data, underscoring how quickly new threats can proliferate using obfuscation as an evasion technique to evade legacy controls. The findings show that while novel exploits emerge, attackers continue to rely heavily on older, widely used vulnerabilities in browsers, web frameworks, and open-source tools.  

“Across Q2, the report’s findings point to a rise in evasive malware over encrypted channels as attackers work hard to bypass detection and maximize impact,” said Corey Nachreiner, chief security officer, WatchGuard Technologies. “For resource-constrained MSPs and lean IT teams, this shift means the real challenge is adapting quickly with powerful measures. Consistent patching, proven defenses, and advanced detection and response technologies that can act quickly remain the most effective countermeasures to mitigate these threats.” 

Additional key findings from WatchGuard’s Q2 2025 Internet Security Report include:  

  • Brand new, unique malware threats rose 26%, showing how common packing encryption, a type of malware evasion, is with threat actors. These polymorphic threats evade signature-based detection, driving higher hits by WatchGuard’s advanced services such as APT Blocker (Advanced Persistent Threat Blocker) and IAV numbers.  
  • The Threat Lab unexpectedly identified two USB-based malware threats: PUMPBENCH, a remote access backdoor and HIGHREPS, a loader. Both deployed a coin miner, XMRig, which mines Monero (XMR), and are likely tied to hardware wallet usage among crypto holders. 
  • Ransomware declined by 47%, reflecting a shift toward fewer but more impactful attacks on high-profile targets that result in larger consequences. Notably, the number of active extortion groups has increased, with Akira and Qilin being among the most aggressive. 
  • Droppers dominated network malware. Seven of the top ten detections were first-stage payloads, including Trojan.VBA.Agent.BIZ and credential stealer PonyStealer, exploiting user-enabled macros for initial compromise. The infamous Mirai botnet also resurfaced after five years, concentrated mostly in APAC. The dominance of droppers indicates attackers' preference for multi-stage infections.   
  • Zero-day malware continues to dominate, making up over 76% of all detections and nearly 90% of encrypted malware. These findings underscore the need for advanced detection capabilities beyond signatures, particularly for threats concealed within TLS traffic.  
  • DNS-based threats persisted, including domains tied to the DarkGate remote access trojan (RAT), a loader malware that acts as a RAT, reinforcing DNS filtering as a critical defensive layer. 

Consistent with the Threat Lab’s previous quarterly research updates, the data in this quarterly report is based on anonymized, aggregated threat intelligence from active WatchGuard network and endpoint products whose owners have opted to share in direct support of WatchGuard’s research efforts. 

For a more in-depth view of WatchGuard’s research, download the complete Q2 2025 Internet Security Report.  

About WatchGuard Technologies    

WatchGuard® Technologies, Inc. is a global leader in unified cybersecurity. Our Unified Security Platform® is uniquely designed for managed service providers to deliver world-class security that increases their business scale and velocity while also improving operational efficiency. Trusted by more than 17,000 security resellers and service providers to protect more than 250,000 customers, the company’s award-winning products and services span network security and intelligence, advanced endpoint protection, multi-factor authentication, and secure Wi-Fi. Together, they offer five critical elements of a security platform: comprehensive security, shared knowledge, clarity & control, operational alignment, and automation. The company is headquartered in Seattle, Washington, with offices throughout North America, Europe, Asia Pacific, and Latin America. To learn more, visit WatchGuard.com.    

For additional information, promotions, and updates, follow WatchGuard on X (@WatchGuard), on Facebook, or on the LinkedIn Company page. Also, visit our InfoSec blog, Secplicity, for real-time information about the latest threats and how to cope with them. Subscribe to The 443 – Security Simplified podcast, or wherever you find your favorite podcasts.    

WatchGuard is a registered trademark of WatchGuard Technologies, Inc. All other marks are property of their respective owners.   


WatchGuard Technologies, Inc 
watchguard@inkhouse.com

Recent Quotes

View More
Symbol Price Change (%)
AMZN  220.69
+3.55 (1.63%)
AAPL  271.49
+5.24 (1.97%)
AMD  203.78
-2.24 (-1.09%)
BAC  51.56
+0.56 (1.10%)
GOOG  299.65
+9.67 (3.33%)
META  594.25
+5.10 (0.87%)
MSFT  472.12
-6.31 (-1.32%)
NVDA  178.88
-1.76 (-0.97%)
ORCL  198.76
-11.93 (-5.66%)
TSLA  391.09
-4.14 (-1.05%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.