• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Upcoming Events
    • Wealth & Tech Summit, Dubai (May 8, 2026)
    • Digital Assets Forum, Abu Dhabi (May 13, 2026)
    • Digital Assets Week in USA, New York (May 13-14, 2026)
    • Online Trading Expo, Hong Kong (May 27-28, 2026)
    • Money20/20, Amsterdam (June 2-4, 2026)
    • NZCryptoCon, Auckland (June 6-7, 2026)
    • Blockchain Futurist Conference, Toronto (July 21-22, 2026)
    • Wiki Finance Expo, Hong Kong (July 23-24, 2026)
    • Digital Assets Week in London (October 6-7, 2026)
    • 5th Fintech Week & Expo, Frankfurt (October 7-8, 2026)
    • iCrypto Awards: People’s Choice, Dubai (December, 2026)
  • Past Events

Crypto Reporter

Online magazine about cryptocurrencies, NFTs, DeFi, GameFi and other blockchain technologies

Join us on Telegram: https://t.me/crypto_reporter
  • News
    • News Feed
    • Cryptocurrencies
      • Bitcoin
      • Altcoins
    • Payment solutions
    • Exchanges
      • Binance
      • bitFlyer
      • Bitfinex
      • CBOE
      • CME
      • Coinbase
      • Coincheck
      • Coinfloor
      • Nasdaq
      • Poloniex
    • Regulations
      • Australia
      • Belarus
      • China
      • Europe
      • India
      • Iran
      • Israel
      • Japan
      • North Korea
      • Philippines
      • Portugal
      • Russia
      • South Korea
      • Thailand
      • Turkey
      • Venezuela
      • Vietnam
      • United States
    • Blockchain platforms
    • Crypto news in brief
    • Stats & trends
    • Reviews
      • Ambrosus
      • ATN
      • Dash
      • Green Power Exchange
      • Power Ledger
      • ShapeShift
      • Waltonchain
      • Cryptocurrency market capitalization can top 4 trillion USD, under conservative estimates
    • Opinion
    • Sponsored
  • Press Releases

New WatchGuard Threat Lab Report Discovers 94% Increase in Network Malware as Cybercriminals Exploit Advanced, Encrypted Connections

April 10, 2025 By GlobeNewswire

Other key findings show an increase in crypto miner detections, a spike in zero-day malware, a drop in endpoint malware, a rise in Linux-based threats, and more.

SEATTLE, April 10, 2025 (GLOBE NEWSWIRE) -- WatchGuard® Technologies, a global leader in unified cybersecurity, today released the findings of its latest Internet Security Report, a quarterly analysis detailing the top malware, network, and endpoint security threats observed by the WatchGuard Threat Lab researchers during the fourth quarter of 2024. 

The report’s key findings include a 94% (quarter-over-quarter) increase in network-based malware detections, reflecting a steady rise in threats. At the same time, the data shows an increase in all malware detections, including a 6% increase in Gateway AntiVirus (GAV) detections and a 74% increase in Advanced Persistent Threat (APT) Blocker detections, the most significant rises came from proactive machine learning detection offered by IntelligentAV (IAV) at 315%, indicating the growing role in more proactive anti-malware services catching sophisticated, evasive malware, like zero-day malware, when it comes from encrypted channels. The significant upticks in evasive hits suggest attackers are leaning harder into obfuscation and encryption, challenging traditional defenses.

The Threat Lab also observed a significant increase in crypto miner detection at 141% quarter over quarter. Cryptocurrency mining is a natural process for acquiring cryptocurrency on some blockchains, including Bitcoin. A malicious coin miner can look like executing software that installs a coin miner without the user’s knowledge or consent. As the price and popularity of Bitcoin go up, crypto miner detections also stand out as a malicious tactic used by threat actors.  

“The findings from our Q4 2024 Internet Security Report reveal a cybersecurity landscape where attackers are both continuously relying on old habits and low-hanging fruit vulnerabilities and flaws that are easy to exploit while also leveraging evasive malware techniques to evade traditional defenses,” said Corey Nachreiner, chief security officer, WatchGuard Technologies. “The data illustrates the importance of staying vigilant with the basics: proactively keep systems updated, monitor for abnormal activity, and use layered defenses to catch the inevitable exploit attempts across networks and endpoints. By doing so, businesses can greatly mitigate the threats demonstrated this quarter and be prepared for what adversaries and the evolving threat landscape may bring.” 

Additional key findings from WatchGuard’s Q4 2024 Internet Security Report include: 

  • In Q4, Zero-Day malware rebounded to 53%, up significantly from its all-time low of 20% in Q3. This reinforces the report’s earlier observation that malware increasingly comes in encrypted connections, with these encrypted channels typically delivering more sophisticated and evasive threats.

  • Total unique malware threats are significantly down for the quarter, at a historic 91% decrease. This is likely due to a reduction in one-off targeted attacks and an increase in generic malware. However, fewer threats do not mean that the threats that attempt to slip through defenses will be simple attacks if not addressed quickly and diligently. 

  • Network attacks declined 27% from the previous quarter. The Threat Lab findings show that many tried-and-true exploits persisted as top attacks this quarter, underscoring that attackers stick with what they know works.  

  • The top phishing domains list remained unchanged from the previous quarter, highlighting the continued use of persistent and high-impact phishing infrastructure. The SharePoint-themed phishing domains, which often mimic legitimate login portals to harvest credentials, suggest that attackers still exploit business email compromise (BEC) tactics to target organizations relying on Office 365 services. 

  • Living off-the-land attacks (LotL), which exploit legitimate system tools like PowerShell, Windows Management Instrumentation (WMI), or Office macros instead of relying on external malware to load malware, are trending. This can be seen in 61% of endpoint attack techniques leveraging PowerShell injection and scripts, accounting for nearly 83% of all endpoint attack vectors. Of that ~83%, 97% were from PowerShell, again pointing to PowerShell being responsible for the vast majority of threat actors’ avenues of attack. 

  • Over half of the top 10 network detections are generic signatures, which catch common web app flaws. This trend underscores that attackers are going after the “bread and butter” style attacks in mass. 

Consistent with WatchGuard’s Unified Security Platform® approach and the WatchGuard Threat Lab’s previous quarterly research updates, the data analyzed in this quarterly report is based on anonymized, aggregated threat intelligence from active WatchGuard network and endpoint products whose owners have opted to share in direct support of WatchGuard’s research efforts.

For a more in-depth view of WatchGuard’s research, download the complete Q4 2024 Internet Security Report here. 

About WatchGuard Technologies, Inc. 

WatchGuard® Technologies, Inc. is a global leader in unified cybersecurity. Our Unified Security Platform® approach is uniquely designed for managed service providers to deliver world-class security that increases business scale and velocity while improving operational efficiency. Trusted by more than 17,000 security resellers and service providers to protect over 250,000 customers, the company’s award-winning products and services span network security and intelligence, advanced endpoint protection, multi-factor authentication, and secure Wi-Fi. Together, they offer five critical elements of a security platform: comprehensive security, shared knowledge, clarity & control, operational alignment, and automation. The company is headquartered in Seattle, Washington, with offices throughout North America, Europe, Asia Pacific, and Latin America. To learn more, visit WatchGuard.com.

For additional information, promotions, and updates, follow WatchGuard on Twitter (@WatchGuard), Facebook, or LinkedIn Company page. Also, visit our InfoSec blog, Secplicity, for real-time information about the latest threats and how to cope with them. Subscribe to The 443 – Security Simplified podcast wherever you find your favorite podcasts. 

WatchGuard is a registered trademark of WatchGuard Technologies, Inc. All other marks are property of their respective owners.

CONTACT: Anthony Cogswell
WatchGuard Technologies, Inc 
Anthony.Cogswell@watchguard.com

Filed Under: News Feed

Primary Sidebar

Follow Us

Press Releases

Velotrade Opens Full API Access to Funded Crypto Traders

May 19, 2026

Stablewatch incubates Osero with a $13.5M raise to power stablecoin earn products

May 19, 2026

NEAR AI Brings Private USDC Stablecoin Payments to the Agentic Economy

May 19, 2026

Inca Digital Partners with the Republic of the Marshall Islands to Deliver Market Surveillance and Intelligence for USDM1, the World’s First Digitally Native Sovereign Bond

May 19, 2026

The 10 Best Press Release Distribution Services to Boost Your Brand Authority in 2026

May 19, 2026

WFIS Vietnam 2026

Online Trading Expo

Money20/20

Blockchain Futurist Conference

Wiki Finance Expo

5th Fintech Week & Expo 2026

iCrypto Awards

Footer

Crypto Reporter is an online magazine about cryptocurrencies, NFTs, DeFi, GameFi and other blockchain technologies
About us
Contact us
Submit press-release

Search

2017-2026 Crypto Reporter