This concerning figure is just one of the myriad findings from Netskope’s most recent Cloud and Threat Report: Global Cloud and Web Malware Trends, published to provide enterprises worldwide with intelligence and insight on active malware threats.
Persisting as the go-to tactic for threat actors to establish a foothold in enterprise organisations is social engineering — the act of influencing, deceiving, or manipulating a victim to compromise security and consequently gain access to personal or financial information.
In Q1, trojans — malware samples that are disguised as legitimate files to trick users into downloading them — accounted for 60% of all malware downloads, indicating that it continues to be a popular technique for threat actors and has a high success rate. Phishing downloads, meanwhile, accounted for 13% of all malware downloads in 2023’s first quarter.
In terms of newer developments, the report pointed to the rise in how search engine data voids are being weaponised. A data void is a search query that turns up little to no results, meaning that content matching the query has a high likelihood of being displayed near or at the top of the result set.
On this rising trend, Netskope says that threat actors have “cleverly crafted malware payloads and malware delivery sites to exploit data voids, using those uncommon combinations of search terms to trick victims into downloading malware.”
In fact, in Q1, nearly 10% of all malware downloads were referred from search engines because of weaponised data voids, and also malicious ads appearing alongside search engine results.
The cybersecurity firm’s research also highlighted that one notable way in which threat actors are attempting to fly under the radar is by distributing malware over widely-used enterprise channels. This is so that the malware transfer may potentially bypass security controls and blend in with normal traffic.
With this in mind, cloud enterprise apps — such as OneDrive, Sharepoint, and Amazon S3 — are becoming increasingly popular channels for malware delivery, with 55% of HTTP/HTTPS malware downloads coming from cloud apps in Q1, marking a 35% increase over Q1 2022.
Recommended
- DIGIT Leader | Driving Data-led Decision-making in Government
- Report: Most UK Businesses Comfortable with Tech Making Decisions
- Report: FTSE 350 Cybersecurity Posture Has Improved
The report also underscored how malware detection remains to be a challenge for enterprises, especially as the number of malware families and variants are constantly growing.
Specifically, Netskope detected downloads of more than 60,000 distinct malware types in Q1, 72% of which were either new variants of existing families or new malware families entirely.
In response to the ever-evolving threat of malware, Netskope recommends undertaking a multitude of actions and interventions, such as: inspecting all HTTP/HTTPS downloads; ensuring security controls recursively inspect the content of popular archive files (like ZIPs); as well as providing education to users about social engineering techniques, among other strategies.
To read Cloud and Threat Report: Global Cloud and Web Malware Trends and its recommendations in full, click here.





