Security researchers have detected a 300% increase in endpoint malware as threat actors continue to target legitimate web services and documents, all while using increasingly sophisticated tactics to execute their attacks.
Cybersecurity firm WatchGuard Technologies issued the warning in its latest Internet Security Report, which details the top malware, network, and endpoint security threats observed over the third quarter of 2024.
The study found that endpoint malware detections were up significantly compared to Q2 2024, this was coupled with a 74% decrease in threats blocked per 100k active machines, suggesting a flood of homogenous spam-like malware arriving on endpoints, likely separate malware campaigns with the same payload.
The report also found that network-based malware attacks fell by 15% from Q3 2024, a decline which WatchGuard said could be down to attackers creating less new or unique malware than in previous quarters, and instead turning to a wider breadth of established techniques to infect devices.
However, over half (52%) of malware was found to arrive over TLS-encrypted connections, highlighting the importance of thorough HTTPS inspections at network perimeters.
Notably, as cryptocurrency has been rising in value, attackers were increasingly witnessed using cryptominers – malware that hides on user’s devices to steal resources in order to mine cryptocurrencies – however all the top ten samples of cryptominers collected by WatchGuard were found to exhibit other malicious behaviours.
Threat actors were also found adapting their ‘traditional’ attack methods. While Microsoft applications have long been targets for malicious actors, anti-macro protections introduced for Word, Excel, and PowerPoint files have led attackers to now use OneNote files to deliver Qbot, a remote access botnet trojan.
At the same time, attackers are scaling up their exploits of vulnerabilities in WordPress plug-ins, hoping to gain control over websites and leverage their reputations to trick users into making malicious downloads like SocGholish, which issues false prompts to update browsers in order to execute malware.
With WordPress hosting more than 488.6 million websites – 43% of all websites on the internet – such tactics potentially threaten millions of people all over the world.
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Ransomware Crisis Escalating Globally, New Report Shows
- Over Half of Hacked UK Firms Pay Ransom
“These findings illustrate how quickly the threat landscape can evolve, so it’s important to utilize full, defense-in-depth cybersecurity solutions that can quickly catch old threats and adapt to new ones in real time,” said Corey Nachreiner, chief security officer at WatchGuard Technologies.
“Organisations of all sizes should consider adopting AI-powered threat detection to spot unexpected traffic patterns and reduce dwell time, ultimately reducing the cost of a breach but also maintaining their traditional antimalware controls too.”





