Glossary

Fileless Malware

Most malware installs files on your computer that antivirus can find. Fileless malware is sneakier - it lives only in your computer's memory and uses built-in Windows tools to do bad things. When you restart, it's gone from memory, but it often finds ways to come back.

What is Fileless Malware?

Malware that operates entirely in memory without writing files to disk, using legitimate system tools and processes to carry out malicious activities while evading traditional antivirus detection.

Why Should You Care?

Fileless malware defeats signature-based antivirus detection by operating largely in memory and through legitimate system tools, allowing attackers to establish persistent access and steal credentials or data before security teams identify the intrusion. Organizations relying solely on traditional file-based scanning leave themselves vulnerable to extended dwell times, giving attackers time to exfiltrate sensitive information, move laterally, or establish backdoors. This class of threat drives investment in behavioral detection tools like endpoint detection and response (EDR) rather than reliance on antivirus alone.

Is your business exposed?

Real-World Example

Kovter, a malware campaign active in the mid-2010s, evolved into a largely fileless threat that hid its configuration in the Windows Registry and used PowerShell and script-based techniques to maintain persistence without writing a traditional executable to disk. Once established, it injected into legitimate processes and conducted ad fraud while evading standard antivirus tools, demonstrating how fileless attacks can persist by leveraging built-in Windows utilities that system administrators trust.

How to Protect Against Fileless Malware

  1. 1.

    Deploy EDR solution with memory scanning

  2. 2.

    Enable PowerShell logging

  3. 3.

    Restrict administrative tool usage

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required