Critical severity Malware

Fileless Malware

Runs entirely from memory using legitimate system tools, leaving almost nothing on disk.

Overview

The payload lives in the registry, PowerShell or WMI and is re-hydrated on every boot, so static file scanning has nothing to look at.\nThe trick is living off the land: cmd, certutil, mshta and rundll32 do the work, all signed by the vendor.\nDetection shifts to behavioural telemetry, script-block logging and command-line auditing.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Encoded PowerShell launched from Office documents
  • WMI permanent event subscriptions
  • Registry values containing script payloads

Controls that stop it

  • Keep Tested, Offline Backups

    Backups are the difference between an incident and a catastrophe. Store copies offline or on immutable storage the production identity cannot modify, encrypt them, and restore-test on a schedule. A backup you have never restored is a hypothesis, not a recovery plan. This is the control that neutralises ransomware and wipers regardless of how the intrusion began.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used