Categories: Top News

New WatchGuard Threat Lab Report Finds 300% Increase in Endpoint Malware as Threat Actors Target Legitimate Web Services and Documents

Other key findings include a resurgence of cryptomining malware, an increase in signature-based and social engineering attacks, and increased malware attacks across EMEA

SEATTLE, Feb. 19, 2025 (GLOBE NEWSWIRE) — WatchGuard® Technologies, a global leader in unified cybersecurity, today released the findings of its latest Internet Security Report, a quarterly analysis detailing the top malware, network, and endpoint security threats observed by the WatchGuard Threat Lab researchers during the third quarter of 2024.   

The report’s key findings include a 300% increase quarter over quarter of endpoint malware detections, highlighted by growing threats that exploit legitimate websites or documents for malicious purposes as threat actors turn to more social engineering tactics to execute their attacks. While Microsoft documents like Word and Excel have long been targets for deceiving users into downloading malicious software, strict anti-macro protections on Word, Excel, and PowerPoint Office files have led attackers to now use OneNote files to deliver Qbot (a remote access botnet trojan). Another top threat that exploits legitimate services includes new attacks on WordPress plug-in vulnerabilities. Threat actors exploit these vulnerabilities to gain control over websites and leverage their reputation to host malicious downloads like SocGholish, which deceives users with false prompts to update their browsers and then execute malware. WordPress hosts more than 488.6 million websites worldwide, which comprises 43% of all websites on the Internet.  

The Threat Lab also observed a rise in threat actors utilizing cryptominers this quarter, many of which were capable of additional malicious behaviors. Cryptominers are malware that hides on the user’s device and steals its computing resources to mine for online currencies such as Bitcoin. As cryptocurrency rises again in value and popularity, cryptomining malware is also regaining popularity. 

“The findings from our Q3 2024 Internet Security Report demonstrated a dramatic shift in traditional versus evasive malware threats,” said Corey Nachreiner, chief security officer, WatchGuard Technologies. “These findings illustrate how quickly the threat landscape can evolve, so it’s important to utilize full, defense-in-depth cybersecurity solutions that can quickly catch old threats and adapt to new ones in real time. Organizations of all sizes should consider adopting AI-powered threat detection to spot unexpected traffic patterns and reduce dwell time, ultimately reducing the cost of a breach but also maintaining their traditional antimalware controls too.” 

Additional key findings from WatchGuard’s Q3 2024 Internet Security Report include:  

  • This quarter, signature-based detections increased by 40% as threat actors turned to more social engineering tactics to execute their attacks. This growth underscores the rising prevalence of traditional malware as attackers refine their strategies to exploit legacy systems or widespread vulnerabilities.
  • EMEA accounted for 53% of all malware attacks by volume, doubling from the previous quarter. Meanwhile, the Asia Pacific region accounted for the most network attack detections, with 59% targeting the area.   
  • Malware attacks declined by 15% from the previous quarter. The Threat Labs findings also demonstrate that attackers created less new or unique malware than in prior quarters but are using a wider breadth of malware techniques instead to infect devices.  
  • Only 20% of malware detections evaded signature-based detection methods. This was a significant departure from normal for what we call “zero-day malware,” which requires more proactive techniques to catch. 
  • While ransomware continued to trend downward in recent quarters, Threat Labs data shows more ransomware operators this quarter than in Q2 of 2024. Threat actors used a wider range of existing tactics to deliver ransomware rather than creating new attack avenues.      
  • Endpoint malware detections were up significantly this quarter with a 300% increase compared to Q2. This increase was coupled with a 74% decrease in threats blocked per 100k active machines, suggesting a flood of homogenous spam-like malware arriving on endpoints, likely separate malware campaigns with the same payload. 

Consistent with WatchGuard’s Unified Security Platform® approach and the WatchGuard Threat Lab’s previous quarterly research updates, the data analyzed in this quarterly report is based on anonymized, aggregated threat intelligence from active WatchGuard network and endpoint products whose owners have opted to share in direct support of WatchGuard’s research efforts. 

For a more in-depth view of WatchGuard’s research, download the complete Q3 2024 Internet Security Report here: https://www.watchguard.com/wgrd-resource-center/security-report-q3-2024 

 

About WatchGuard Technologies, Inc.  

WatchGuard® Technologies, Inc. is a global leader in unified cybersecurity. Our Unified Security Platform® approach is uniquely designed for managed service providers to deliver world-class security that increases their business scale and velocity while also improving operational efficiency. Trusted by more than 17,000 security resellers and service providers to protect more than 250,000 customers, the company’s award-winning products and services span network security and intelligence, advanced endpoint protection, multi-factor authentication, and secure Wi-Fi. Together, they offer five critical elements of a security platform: comprehensive security, shared knowledge, clarity & control, operational alignment, and automation. The company is headquartered in Seattle, Washington, with offices throughout North America, Europe, Asia Pacific, and Latin America. To learn more, visit WatchGuard.com.  
  

For additional information, promotions and updates, follow WatchGuard on Twitter (@WatchGuard), on Facebook, or on the LinkedIn Company page. Also, visit our InfoSec blog, Secplicity, for real-time information about the latest threats and how to cope with them at www.secplicity.org. Subscribe to The 443 – Security Simplified podcast at Secplicity.org, or wherever you find your favorite podcasts.  

  

WatchGuard is a registered trademark of WatchGuard Technologies, Inc. All other marks are property of their respective owners. 

 

CONTACT: Chris Warfield
WatchGuard Technologies, Inc 
chris.warfield@watchguard.com

GlobeNewswire

GlobeNewswire, is one of the world's largest newswire distribution networks, specializing in the delivery of corporate press releases financial disclosures and multimedia content to the media, investment community, individual investors and the general public.

Recent Posts

The opinion of the Supervisory Board of Enefit Green AS on the voluntary takeover bid made by Eesti Energia AS on 8 April 2025.

Hereby we publish the opinion of the Supervisory Board of Enefit Green AS on the…

2 hours ago

Bitcoin ‘breaking out’ as it retakes $87K after early April slump

Bitcoin is now more correlated with gold, which reached another all-time high, while the US…

12 hours ago

Bitcoin price surging on Sunday evening

If BTC can break through the resistance level of $86,000, it may target higher levels,…

12 hours ago

ROSEN, RECOGNIZED INVESTOR COUNSEL, Encourages Zynex, Inc. Investors to Secure Counsel Before Important Deadline in Securities Class Action – ZYXI

NEW YORK, April 20, 2025 (GLOBE NEWSWIRE) -- WHY: Rosen Law Firm, a global investor rights…

16 hours ago

Writer/painter-turned cultural heritage preserver behind Spring Festival’s UNESCO heritage status success

Global Times: Feng Jicai leads efforts to preserve China's cultural heritage through art, literature, and…

17 hours ago

Boston Hemp Launches New Line of Premium THCa Concentrates

Hanover, MA , April 20, 2025 (GLOBE NEWSWIRE) -- Boston Hemp Inc., a leader in…

18 hours ago

This website uses cookies.