MSSP, MSP, Managed Security Services, Generative AI, Attack surface management, Data Security, SOC, EDR, MDR, XDR

Unique, Encrypted Malware Grows, Putting Pressure on MSSPs and MSPs: WatchGuard

Privacy concept: pixelated words Malware on digital background, 3d render

Organizations and services providers are seeing a startling spike in new malware that is increasingly encrypted and obfuscated, making it more difficult to detect and putting greater pressure on MSSPs and MSPs to adopt more proactive and unified approaches to defending clients, according to WatchGuard Technologies.

WatchGuard’s Internet Security Report H2 2025 reveals that the appearance of unique endpoint malware grew every quarter last year and jumped 1,548% between the third and fourth quarters. In addition, bad actors are evolving their tactics, moving away from malicious scripts and more often adopting Windows binaries and living-off-the-land (LotL) tools, using trusted processes to avoid detection.

What this highlights for MSSPs and MSPs is the need for more modern security strategies that include capabilities like endpoint protection, detection, and response, and AI-based threat detection, according to WatchGuard executives. It will also require continuous monitoring.

“With increasing volumes of new malware, managed detection and response [MDR] services within a SOC (security operations center) are critical for identifying and remediating more sophisticated malware,” Corey Nachreiner, WatchGuard’s chief security officer, told MSSP Alert. “MSSPs offer full SOC-as-a-service, and MSPs often offer MDR services that can provide SMBs with 24/7 monitoring to protect against the latest threats.”

SMBs Need Help

This is particularly true for SMBs, which don’t have the same budgets or capabilities compared to larger organizations when dealing with an increasingly complex cyber threat landscape. Many of them are turning to security services providers to not only deliver and manage their cybersecurity environments but also to act as trusted advisers.

“Most average businesses, aside from enterprises, do not have a mature cybersecurity department,” Nachreiner said. “Some organizations do not even have a dedicated security professional, and it is just another job for IT. This is no longer enough in the modern threat landscape. Sophisticated threats require endpoint detection and response (EDR) and network detection and response (NDR) products to detect them, and these products often require monitoring.”

WatchGuard, which offers cybersecurity tools for MSPs, collects threat intelligence for its reports from its network security, endpoint, and DS filtering products. What the company found is an acceleration in threats from bad actors that are more encrypted and designed to better bypass protections.

Encrypted Malware on the Rise

Along with the sharp increase in new endpoint malware, which the report’s authors wrote suggested “threat actors were focusing on new and evasive malware during the end of the
year” - WatchGuard also saw an almost 2,000% increase in malware detected over TLS, with about 96% of blocked malware being delivered over TLS.

The technique allows bad actors to evade firewalls, run cover command-and-control communications, and steal data without triggering alerts, and has been on the rise in recent years. Zscaler’s ThreatLabz analysts found in 2024 that 87.2% of all blocked attacks were encrypted.

“This near-total reliance on encryption continues to create significant blind spots for organizations that do not perform HTTPS inspection,” the WatchGuard report’s authors wrote, adding that the surge of malware delivered over TLS "reflects new or intensified campaigns leveraging advanced obfuscation and packing techniques specifically designed to exploit
encrypted channels.”

Such threats reinforce the need for key defense priorities, from enabling TLS inspection for regaining visibility into the traffic to including advanced sandboxing to protect against the growing number of evasive and zero-day threats hiding in it.

Zero-Days, Ransomware Evolving

There was also a change in the amount of zero-day malware detected. According to the report, 23% of malware were zero-days. Such malware had significantly increased in the first half of 2025, but the number declined in the last six months of the year.

“Adding to this, zero-day malware only accounted for 16% of malware detected over encrypted connections, showing an unusual decline in evasive malware there, too,” the authors wrote.

In another finding, the incidence of ransomware declined toward the end of the year. Detection was up a bit in the third quarter but dropped by 68.24% over the year.

“Ransomware is not going away, but we suspect threat actors are focusing on big game hunting with very high ransom demands,” they wrote. “This does not mean ransomware extortions are down; it just means ransomware attackers are targeting victims instead of sending ransomware to every potential victim.”

That said, cryptocurrency miners were on the upswing as last year ended, and that popularity will likely continue because it’s an easy way to take money from infected victims, according to the report.

Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds