What is fileless malware?¶
Fileless malware is malicious activity that relies mainly on memory, scripts or existing system components instead of installing a conventional executable file. The label does not mean that the incident leaves no evidence or that no file was ever involved.
An offender may use a command shell, PowerShell, a document macro, a management tool or code injected into another process. Instructions can be downloaded directly into memory, stored in a registry value, recovered from a scheduled task or supplied through a remote session. Some stages may be fileless while another stage creates files, logs or configuration changes.
Where the evidence moves¶
Traditional file scanning is less effective when there is no stable payload on disk. The evidential focus shifts towards the activity that loaded and ran the instructions:
- memory captures and active process information;
- process creation, parent-child relationships and command lines;
- script-block, shell and interpreter logs;
- registry values, scheduled tasks, services and other launch points;
- authentication and remote-management records;
- network requests that obtained commands or payloads; and
- files created, accounts used or settings changed as a result.
These sources can show a chain even when the original code has disappeared: a document launches an interpreter, the interpreter contacts a server, and a new process accesses data. That sequence is usually more informative than the broad label fileless.
Volatility and interpretation¶
Memory-resident material can be lost when a device is restarted or a process ends. If it is safe and lawful to do so, volatile evidence may therefore need to be preserved before routine remediation changes the system. The action and its timing should be recorded because collection itself can alter live state.
Legitimate administrators use the same interpreters and management components. Their presence is not proof of malware. The important questions are what instructions ran, under which account, from what source, and with what result. Encoded or obfuscated commands may indicate concealment, but the decoded content and actual execution still need to be demonstrated.
Key takeaway
Fileless activity reduces reliance on a conventional malware file; it does not erase the process, script, memory, network and configuration records needed to explain execution and effect.