Half of Q1's malware traffic observed by Sophos was TLS encrypted, hiding inside legit requests to legit services

It's just a tool.

Sure, nowadays, all protocols use TLS, whether legitimate, confidential, criminal or just cat pictures. That's a good thing and, more importantly, there is no more point moaning about it than that it snows in winter. It isn't going to go away.

Even without TLS, much data is compressed, which makes it just as hard to see what any particular communication contains.

