Organizations and services providers are seeing a startling spike in new malware that is increasingly encrypted and obfuscated, making it more difficult to detect and putting greater pressure on MSSPs and MSPs to adopt more proactive and unified approaches to defending clients, according to WatchGuard Technologies.WatchGuard’s Internet Security Report H2 2025 reveals that the appearance of unique endpoint malware grew every quarter last year and jumped 1,548% between the third and fourth quarters. In addition, bad actors are evolving their tactics, moving away from malicious scripts and more often adopting Windows binaries and living-off-the-land (LotL) tools, using trusted processes to avoid detection.What this highlights for MSSPs and MSPs is the need for more modern security strategies that include capabilities like endpoint protection, detection, and response, and AI-based threat detection, according to WatchGuard executives. It will also require continuous monitoring.“With increasing volumes of new malware, managed detection and response [MDR] services within a SOC (security operations center) are critical for identifying and remediating more sophisticated malware,” Corey Nachreiner, WatchGuard’s chief security officer, told MSSP Alert. “MSSPs offer full SOC-as-a-service, and MSPs often offer MDR services that can provide SMBs with 24/7 monitoring to protect against the latest threats.”
year” - WatchGuard also saw an almost 2,000% increase in malware detected over TLS, with about 96% of blocked malware being delivered over TLS.The technique allows bad actors to evade firewalls, run cover command-and-control communications, and steal data without triggering alerts, and has been on the rise in recent years. Zscaler’s ThreatLabz analysts found in 2024 that 87.2% of all blocked attacks were encrypted.“This near-total reliance on encryption continues to create significant blind spots for organizations that do not perform HTTPS inspection,” the WatchGuard report’s authors wrote, adding that the surge of malware delivered over TLS "reflects new or intensified campaigns leveraging advanced obfuscation and packing techniques specifically designed to exploit
encrypted channels.”Such threats reinforce the need for key defense priorities, from enabling TLS inspection for regaining visibility into the traffic to including advanced sandboxing to protect against the growing number of evasive and zero-day threats hiding in it.
SMBs Need Help
This is particularly true for SMBs, which don’t have the same budgets or capabilities compared to larger organizations when dealing with an increasingly complex cyber threat landscape. Many of them are turning to security services providers to not only deliver and manage their cybersecurity environments but also to act as trusted advisers.“Most average businesses, aside from enterprises, do not have a mature cybersecurity department,” Nachreiner said. “Some organizations do not even have a dedicated security professional, and it is just another job for IT. This is no longer enough in the modern threat landscape. Sophisticated threats require endpoint detection and response (EDR) and network detection and response (NDR) products to detect them, and these products often require monitoring.”WatchGuard, which offers cybersecurity tools for MSPs, collects threat intelligence for its reports from its network security, endpoint, and DS filtering products. What the company found is an acceleration in threats from bad actors that are more encrypted and designed to better bypass protections.Encrypted Malware on the Rise
Along with the sharp increase in new endpoint malware, which the report’s authors wrote suggested “threat actors were focusing on new and evasive malware during the end of theyear” - WatchGuard also saw an almost 2,000% increase in malware detected over TLS, with about 96% of blocked malware being delivered over TLS.The technique allows bad actors to evade firewalls, run cover command-and-control communications, and steal data without triggering alerts, and has been on the rise in recent years. Zscaler’s ThreatLabz analysts found in 2024 that 87.2% of all blocked attacks were encrypted.“This near-total reliance on encryption continues to create significant blind spots for organizations that do not perform HTTPS inspection,” the WatchGuard report’s authors wrote, adding that the surge of malware delivered over TLS "reflects new or intensified campaigns leveraging advanced obfuscation and packing techniques specifically designed to exploit
encrypted channels.”Such threats reinforce the need for key defense priorities, from enabling TLS inspection for regaining visibility into the traffic to including advanced sandboxing to protect against the growing number of evasive and zero-day threats hiding in it.