Site navigation

Report: AI-powered Malware Detection Sees 315% Increase

Graham Turner

,

network malware surge
Other key findings show an increase in crypto miner detections, a spike in zero-day malware, a drop in endpoint malware, a rise in Linux-based threats, and more.

Cybersecurity firm WatchGuard® Technologies  has released the findings of its latest Internet Security Report, a quarterly analysis detailing the top malware, network, and endpoint security threats observed by the WatchGuard Threat Lab researchers during the fourth quarter of 2024.

The report’s key findings include a 94% (quarter-over-quarter) increase in network-based malware detections, reflecting a steady rise in threats.

At the same time, the data shows an increase in all malware detections, including a 6% increase in Gateway AntiVirus (GAV) detections and a 74% increase in Advanced Persistent Threat (APT) Blocker detections, the most significant rises came from proactive machine learning detection offered by IntelligentAV (IAV) at 315%, indicating the growing role in more proactive anti-malware services catching sophisticated, evasive malware, like zero-day malware, when it comes from encrypted channels.

The significant upticks in evasive hits suggest attackers are leaning harder into obfuscation and encryption, challenging traditional defenses.

The Threat Lab also observed a significant increase in crypto miner detection at 141% quarter over quarter. Cryptocurrency mining is a natural process for acquiring cryptocurrency on some blockchains, including Bitcoin.

A malicious coin miner can look like executing software that installs a coin miner without the user’s knowledge or consent. As the price and popularity of Bitcoin go up, crypto miner detections also stand out as a malicious tactic used by threat actors.

Beyond this, the report reveals several notable trends.

Zero-day malware made a strong return in Q4, rising to 53% after dropping to an all-time low of 20% in Q3. This uptick reinforces earlier findings that more malware is being delivered through encrypted connections – channels typically used to carry more sophisticated and evasive threats.

Despite this, the total number of unique malware threats saw a dramatic decline, dropping by 91% – a historic low. This likely reflects a shift away from one-off targeted attacks in favour of more generic malware. However, the report cautions that fewer overall threats do not equate to safer conditions; any threats that do get through can still be highly damaging if not addressed swiftly.

Network attacks also declined, down 27% from the previous quarter. Yet the data suggests that many well-established exploits remained popular among attackers, showing that adversaries continue to rely on proven methods.

The list of top phishing domains remained unchanged from Q3, pointing to the ongoing use of persistent phishing infrastructure. Of particular concern are SharePoint-themed phishing domains, which closely mimic legitimate login portals in order to steal credentials—an approach often used in business email compromise (BEC) attacks targeting Office 365 users.

Living off-the-land (LotL) attacks are increasingly common. These attacks exploit built-in system tools such as PowerShell, Windows Management Instrumentation (WMI), and Office macros, rather than introducing new malware. PowerShell was especially dominant in this trend, with 61% of endpoint attack techniques involving PowerShell injection or scripts.

These techniques accounted for nearly 83% of all endpoint attack vectors – and of those, 97% were tied to PowerShell.


Recommended reading


Finally, over half of the top 10 network detections were generic signatures aimed at identifying common web application flaws. This reinforces the trend of attackers deploying high-volume, low-complexity “bread and butter” attacks to exploit widely known vulnerabilities.

“The findings from our Q4 2024 Internet Security Report reveal a cybersecurity landscape where attackers are both continuously relying on old habits and low-hanging fruit vulnerabilities and flaws that are easy to exploit while also leveraging evasive malware techniques to evade traditional defenses,” said Corey Nachreiner, chief security officer, WatchGuard Technologies.

“The data illustrates the importance of staying vigilant with the basics: proactively keep systems updated, monitor for abnormal activity, and use layered defenses to catch the inevitable exploit attempts across networks and endpoints. By doing so, businesses can greatly mitigate the threats demonstrated this quarter and be prepared for what adversaries and the evolving threat landscape may bring.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data