Malware threats are growing more sophisticated, while legacy cyber defence systems are increasingly unable to keep pace, according to OPSWAT’s newly released 2025 Threat Landscape Report.
The report – based on more than 890,000 scans conducted via the firm’s cloud-based analysis platform, Filescan.io – found a 127% increase in malware complexity over the past year. It also revealed that 1 in every 14 files considered ‘safe’ by older detection systems was later confirmed to be malicious through behavioural analysis.
As cyber attackers shift from brute-force methods to stealthier, evasion-led strategies, OPSWAT argues that conventional antivirus and signature-based tools are no longer sufficient to protect critical infrastructure, enterprise networks and government systems.
“This is not a game of volume anymore – it’s a game of deception,” said Jan Miller, Chief Technology Officer for Threat Analysis at OPSWAT. “Attackers are building malware designed to confuse and delay detection, not overwhelm defences in the traditional sense.”
Stealth, not scale, defines modern malware
The report details a wide array of malware behaviours now evading detection. These include steganography-laced loaders, clipboard hijackers like ClickFix and .NET Bitmap file loaders delivering Snake Keylogger payloads. In several instances, OPSWAT’s analysis identified command-and-control (C2) channels disguised within trusted platforms such as Google services.
According to OPSWAT, the complexity of these malware strains has outstripped the capabilities of traditional tools that rely on static analysis, file reputation or public threat intelligence feeds. The company’s own pipeline reclassified 7.3% of scanned files as malicious, often 24 hours ahead of any signals on open-source intelligence sources.
Campaign-level intelligence gives defenders context
Beyond individual file detection, OPSWAT’s system connects the dots across multiple campaigns. By analysing shared tactics, reused infrastructure and behavioural patterns, the platform delivers broader visibility into adversary strategies.
This campaign-level threat correlation is a departure from older, indicator-based systems that often overwhelm security teams with low-fidelity alerts. OPSWAT claims its approach improves decision-making for defenders, particularly in complex or high-risk environments like OT, energy and healthcare.
The company’s use of an enhanced PE emulator and behaviour-led machine learning resulted in a detection accuracy of 99.97% across all sandbox scans. These technologies, OPSWAT said, are key to identifying threats that do not match known signatures but exhibit suspicious execution behaviour.
A call for adaptive, multilayered defence strategies
The broader implication, OPSWAT warns, is that organisations relying solely on static detection technologies face growing exposure to increasingly modular and evasive malware. The report advocates for integrated, layered security pipelines that combine behavioural analysis, proactive emulation and contextual intelligence.
“For security leaders, the question is no longer whether legacy tools work—they don’t in many cases,” said Miller. “The question is how quickly they can pivot to a detection strategy that adapts in real time.”

