Over the past year, security experts from Webroot scanned over 27 billion addresses, 600 million domains, 4 billion IP addresses, 20 million mobile apps, 10 million connected sensors, and looked at over 9 billion behavioral log records. What they discovered is that in 97% of all detections, each malware is unique to the system it infects, even if it is the same at its core, for different infections, it is the same malware with variations.
Webroot security researchers claim that malicious software carriers intentionally use a technique called polymorphism, which changes a malware in a way to create unique executable files.
This technique is old and can be applied on the server, from where the malware is distributed, before being introduced to each victim, or on the client side, where the malware itself changes with each new infected victim.
This so-called polymorphism technique produces new signatures for each new malware infection and may be the reason why other cybersecurity companies, such as Dell or Panda Security, report seeing new malware numbers – they talked about billions of infections per year and millions per month.
“This tactic creates a significant problem for traditional security approaches, which struggle to discover individual variables, let alone do so in time to stop data breaches and other exposures,” Webroot experts explain.
And things, unfortunately, aren't getting any better. "While polymorphic malware has been around for over a decade, it's now the norm for almost all threats today," explains Grayson Milbourne, Director of Security Intelligence at Webroot.
In 2014, Webroot says it detected an average of about 700 file instances per malware family and nearly 30,000 file instances per PUA (Potentially Unwanted Applications). That changed dramatically in 2015, when the same Webroot researchers said they saw fewer than 100 file instances per malware family and about 260 file instances per PUA.
Webroot says this doesn't mean there aren't any file instances, but the use of polymorphic distribution models has made detecting all variants much more difficult.
More details on polymorphic malware can be found in Webroot's "2016 Threat Brief: Next-Generation Threats Exposed" report, along with other 2015 trends in mobile malware and cyberattacks.

