The speed of malware growth: 26.5 new variants an hour

What if I were to tell you that the threat landscape is changing faster than ever before? According to newly published research from SonicWall, a rather mind-boggling 26.5 new malware variants are being created every hour.

Or, to put it another way, thatโ€™s 637 new, never before seen, malware variants every single day.

Thatโ€™s probably got your attention, but Iโ€™m sorry to report thereโ€™s more to come. Like the fact that 61% of attacks analysed by the SonicWall researchers saw new vulnerabilities being exploited within just two days.ย And encrypted attacks against businesses, created to make detection efforts as difficult as possible, have grown by 80% across 2024.

SMBs are at the sharp end of these attacks, with SonicWall stating that identity, cloud, and credential compromise account for 85% of all actionable alerts.

Thatโ€™s the bad news, but hereโ€™s the worst:ย  While threat actors are moving at an unprecedented pace, as that two-day window mentioned earlier shows, โ€œweโ€™re observing that it takes some organisations 120 to 150 days to apply a critical patch,โ€ SonicWall CEO Bob VanKirk said. โ€œIn 2024,โ€ VanKirk continued, โ€œwe witnessed alarming trends that underscore the urgent need for proactive defense strategies.โ€

SonicWall graphic showing the time it takes for hackers to use new exploit code against businesses
SonicWall graphic showing the time it takes for hackers to use new exploit code against businesses

AI driving malware growth

Part of the problem is, as Iโ€™ve mentioned here at TechFinitive before, the advances in AI-driven attack methodologies. These are now available to threat actors at a cost that makes them profitable when targeting not just large enterprises but the smaller end of the business market as well.ย 

โ€œSMBs are facing a storm of cyber threats, as attackers leverage automation, AI, and advanced evasion techniques to evade traditional defenses,โ€ the report stated, โ€œas attack surfaces expand and the time to exploit vulnerabilities shrinks, SMBs must prioritise proactive security measures.โ€

Given that the SonicWall intelligence found, on average, organisationsย were under critical attack for 68 days, the time to get proactive is long since overdue.

What that means for your business is that simply reacting to incidents after they have occurred really isnโ€™t an option any longer.ย Instead, you need to be actively identifying threats and mitigating them before they can cause you harm.

That means scanning for vulnerabilities and patching systems in a timely fashion, employing a hunter mentality rather than a prey one.

Unless you do that, Iโ€™m afraid youโ€™re doomed to be part of the shocking statistic list next year.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.