The overall number of malware using SSL to protect their C&C server communications has increased dramatically, a report from Blue Coat has revealed.
Researchers say both the number of malware samples detected each month and the total number of active C&C servers are on the rise. For both categories, the security firm claims to have seen a huge spike in SSL deployment starting in late 2015.
The company explained that it analyzed cybercriminal activity from January 2014 to December 2015 and used data from the SSL Blacklist website.

The report analyzed the detection and infrastructure of common malware families known for using SSL for protection. Some of these malware variants include names such as: Dridex, KINS, Shylock, URLzone, TeslaCrypt, CryptoLocker, TorrentLocker, CryptoWall, Upatre, Gootkit, Geodo, Tinba, Gozi, VMZeus, Redyms, Vawtrack, Qadars, Spambot, Emotee, and Retefe.
The Blue Coat researchers stated:
“Looking at the timing of the increase, it coincided with the start of the holiday season. Therefore, the increase could be attributed to the start of one (or more) large-scale campaigns with infrastructures based on these malware families.
What we would say is the largest jump in C&C servers is likely attributable to malware using Domain Generating Algorithms (DGA) for short-lived domains to build a C&C infrastructure.”
