Malware operators are increasingly using TLS/HTTPS to conceal command-and-control, payload delivery, and data exfiltration traffic, with one report finding TLS-backed malware rising from 23% of Internet-communicating malware in 2020 to nearly 46% in early 2021. Researchers said attackers are blending into normal encrypted traffic by abusing trusted platforms and services including Google, Discord, Pastebin, GitHub, and Telegram, while loaders, droppers, ransomware affiliates, and offensive tools such as Cobalt Strike and Metasploit increasingly rely on encrypted channels. Malware also frequently uses TLS on non-standard ports, reducing the value of simple port-based detection.
A separate analysis of 264 malware families found most SSL/TLS-protected malware communications used HTTPS, while others used SMTP and custom TCP protocols, and that many families relied on self-signed certificates or reused anomalous X.509 attributes that can expose malicious infrastructure. Researchers identified unusual subject names, abnormal serial-number lengths, invalid version fields, and suspicious validity periods as useful detection signals, while noting that some families such as IcedID, AsyncRAT, DcRAT, Vawtrak, and PhantomNet use certificate pinning to resist interception. The findings also show that attackers often deploy valid certificates from trusted authorities, especially Let’s Encrypt, underscoring that certificate metadata and anomaly-based inspection remain important for detecting encrypted malware traffic.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that 696 of 1,067 self-signed malware certificates had already expired as of August 6, 2021. The same analysis found that about 60.4 percent of the malware certificates in its searchable dataset were self-signed.
As of June 29, 2021, Trend Micro found 1,767 of 4,093 malware-related certificates available from queried certificate search engines such as Censys and crt.sh. The dataset supported its analysis of self-signed and CA-issued malware certificates.
Trend Micro's study period ended in June 2021 after examining 264 malware families using SSL/TLS in command-and-control and related communications. The report found HTTPS was the dominant protected protocol, with additional use of SMTP and custom TCP.
Sophos reported that in February 2021, droppers accounted for over 90 percent of observed TLS command-and-control traffic. The report said most TLS-backed malicious activity involved malware retrieving additional payloads.
By early 2021, Sophos telemetry showed nearly 46 percent of malware detected communicating over the Internet used TLS. The increase was linked in part to abuse of legitimate services such as Discord, Pastebin, GitHub, Telegram, and Google cloud services.
Sophos telemetry found that 23 percent of malware detected communicating over the Internet used TLS in 2020. The report framed this as a baseline before a sharp rise in early 2021.
Trend Micro's certificate analysis covered 264 unique malware families observed between May 2019 and June 2021. This marks the start of the study period used for its findings on SSL/TLS use in malware C2.
The Trend Micro brief states that Gozi used the subject "C=XX, ST=1, L=1, O=1, OU=1, CN=*" across hundreds of variants from 2018 through 2021. The certificates typically used 8-byte serial numbers and a 10-year validity period.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.