Cyber-criminals are embracing stealthier tactics to disguise their behaviour and bypass traditional, signature-based detection, with new data showing a spike in evasive malware over the last year.
Cyber firm WatchGuard’s latest Internet Security Report observed a 40% jump in malware hiding inside encrypted traffic over the second quarter of this year, with hackers using more advanced, unique malware, less likely to be caught with behavioural detection.
Even with fewer devices reporting, malware detections arriving over encrypted Transport Layer Security (TLS) connections climbed, up 22% for signature-based threats and 30% for stealthier, more evasive attacks.
Encrypted channels are quickly becoming a preferred attack vector for cyber-criminals, according to WatchGuard. By exploiting TLS, the protocol behind most secure web traffic, hackers are increasingly able to conceal malicious payloads within seemingly legitimate data streams.
More than three-quarters (76%) of the malware WatchGuard assessed bypassed signature-based detection, while 89% of the detected malware over encrypted connections fell into the zero-day category.
Over Q2’25, the number of brand new malware threats rose 26%, showing how common packing encryption, a type of malware evasion, is with threat actors.
Watchguard said that this uptick in never-before-seen malware highlights the need for firms to invest in consistent patching and advanced detection and response tech that can act quickly and provide effective countermeasures.
Recommended reading
- New Report Reveals Rising Threat of Open Source Malware
- Open Source AI Vital to Public Sector Tech Adoption, Says Think Tank
- Open-Source AI: The New Frontier for Developers
“Across Q2, the report’s findings point to a rise in evasive malware over encrypted channels as attackers work hard to bypass detection and maximize impact,” said Corey Nachreiner, chief security officer at WatchGuard Technologies.
“For resource-constrained MSPs and lean IT teams, this shift means the real challenge is adapting quickly with powerful measures.”
Among the few silver linings in the report, WatchGuard found that ransomware over the quarter almost halved, dropping by 47% as hackers made fewer but more impactful attacks on high-profile targets that resulted in larger consequences.
However, the number of active extortion groups increased, with Akira and Qilin being among the most aggressive, and they have refocused on data theft instead of encryption, utilising double and triple extortion tactics.





