The Rise Of Fileless Malware Attack

16 October 2018by Abdallah Alhajeid

The first half of 2018 has seen a 94% increase in the number of fileless cyber attacks on global companies who use the endpoint detection and response (EDR) services of SentinelOne. The latest SentinelOne Enterprise Risk Index Report identifies that fileless attacks using PowerShell increased to a record 5.2 attacks per 1000 endpoints in June. Ransomware attacks also remained popular but fluctuated with numbers ranging from 5.6 to 14.4 attacks per 1000 endpoints between Jan and June.

 

What is fileless malware?

Fileless malware does not involve traditional viruses or worms and leaves little trace of its existence after attacking a target computer. It is designed to evade traditional signature-based antivirus security and to execute illegitimate commands on system software already installed on a computer or server.

Typical fileless attacks use vectors such as email phishing or web browsers and their associated programs (Java, Flash or PDF viewers). Users are tricked into downloading seemingly harmless text files which are then used to execute commands in powerful system tools such as PowerShell and Windows Management Instrumentation (WMI).

In July, the Kaspersky Lab detailed its discovery of PowerGhost fileless malware. PowerGhost is an unintelligible PowerShell script that installs itself in random access memory of the target computer. It then uses the WMI and the Mimikatz data extraction tool to escalate privileges and set up a cryptocurrency mining operation. More recently, researchers have discovered CactusTorch fileless malware that executes and loads malicious .NET files straight from memory.

 

Why is PowerShell a target?

PowerShell is a task automation and configuration management application developed by Microsoft. It is a powerful command-line shell and scripting language and is included in all versions of MS Windows since 2006. This software was also released as open-source and cross-platform in 2016 and now supports macOS, CentOS and Ubuntu. PowerShell allows system administrators to automate tedious and repetitive tasks by creating scripts and combining multiple commands together. Examples of its use include the display all the USB devices installed on one or more computers on a network and the management of other applications running in the background. It is particularly useful for recording and filtering diagnostic data and is used legitimately by digital forensics experts as they investigate suspicious cyber attack activities.

 

Why is PowerShell used by cyber attackers?

It is running on every Windows computer and server in the world.

It is a trusted application and can be used to execute any number of system activities.

All commands run directly in memory and cannot be detected by antivirus software.

Log records of its activity are disabled by default.

 

How does a PowerShell fileless attack work?

A very good example is described by Secrutiny in their recent blog, ‘A surge in PowerShell malware infections through phishing campaign’. The initial infection was delivered via a phishing email which encouraged the recipient to download a bogus order acknowledgement for a recent purchase order. The downloaded .zip file contained two JPG files and an .Ink file which included a PowerShell command.

PowerShell on the infected machine executed this command to achieve the following:

  • Created scheduled tasks to build persistence (keep it running for as long as possible)
  • Encrypted the PowerShell scripts and hide the hacker’s Command and Control (C2) domains
  • Employed anti-analysis techniques
  • Gathered information about processes running on the device
  • Gathered information about the operating system
  • Queried the DNS cache data and compared it against a hard-encoded list of banking domains
  • Captured screen data from all monitors connected to the device

And of course – all this information was communicated covertly back to the Command and Control server (C2) set up by the hacker.

 

How to prevent fileless malware attacks?

Putting security in place to stop legitimate programmes executing illegitimate commands is a major challenge for any organisation. Effective cyber security management always involves the application of security measures that involve people, process and technology.

While many of the activities of a fileless malware attack are automated, the path of attack and system compromise can be slowed or stopped by implementing the following simple measures:

  1. Prevent email infection using anti-phishing technology and user awareness training
  2. Use patch management to ensure PowerShell and WMI is fully up to date
  3. Enable PowerShell logging and Constrained Language mode
  4. Only allow tested, pre-approved scripts to be used
  5. Introduce filtering or blacklisting of compromised websites which may host C2 servers
  6. Use next endpoint detection and response (EDR) to monitor malicious script behaviour

 

——————–

CYBERSHIELD MDR-ENDPOINT is a managed service that combines Next Generation Antivirus, Endpoint Detection & Response, and the latest global cyber threat intelligence information needed to detect and remediate all fileless cyber attacks.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation