Fileless Malware: What Is It and How Can You Protect Yourself From It?

Fileless Malware: What Is It and How Can You Protect Yourself From It? Featured Image

When you think of a virus infecting a system, you may imagine a scenario where someone opens an infected executable file on their PC. This then plants the malware on the system which can then steal information, commence a cryptojacking attack, or do damage to the filesystem. With antivirus being a key part of people’s computers these days, it’s been tricky to get this sort of attack to play out. Recently, we’ve seen a spike in an interesting method of spreading malware – by not using files at all!

Also read: Triada Malware Preinstalled on Low-Cost Android Phones – Here’s How to Beat It

What Is “Fileless Malware?”

fileless-malware-folder

Of course, the malware isn’t totally fileless — it has to come from somewhere after all! The idea here is that the malware works without needing a file on the computer’s filesystem. That way it can operate without needing a “home base” that will give its presence away.

If you think about how a traditional antivirus works, you can see why fileless malware takes this interesting path. An antivirus will check all of the files on a computer’s filesystem for anything that might have been infected. Of course, if the malware hasn’t left any traces on the filesystem itself, there’s no way the scanner can pick up on it and remove it. This is fileless malware’s greatest strength; it’s stealthier than other traditional means.

Where Does It Live?

So if the malware isn’t residing on your computer’s filesystem, where is it being stored? The idea behind fileless malware is that it can operate entirely within the PC’s RAM. The RAM is used to store software while it’s running, so malware can sneak into the RAM where it can do its work while skirting detection. It may get into the system using a vulnerability in existing software, such as through a browser plugin, a hole in the operating system’s defenses, or macros in programs such as Word.

fileless-malware-ram

Living in the RAM means that the malware goes undetected from antiviruses that check the filesystems, but it also comes with a disadvantage. Filesystem-based malware persists when the PC is shut down because hard drives remember data after the computer has been turned off. The RAM, however, gets wiped on shutdown, meaning any RAM-based malware inside of it also perishes. As such, fileless malware is designed to be stealthy and quick so it can perform its job before the PC gets turned off.

How to Avoid It

So now that you know what fileless malware is, how do you avoid being hit by it?

Avoid Untrusted Macros

Try not to install any macros that aren’t from a reputable source. There’s a chance that macros on shady sites will be programmed to take advantage of security holes in the software you’re running the macro in. Only use macros from good, trusted sources.

Keep Software Up to Date

Because fileless macros need a security hole to breach a system, it’s a good idea to keep your software updated with the latest security patches. This includes your operating system which can have native processes hijacked by fileless malware.

Also read: The “Troubleshooter” Malware Scam and How to Fix It

Use a Good Antivirus

fileless-malware-antivirus

A basic antivirus will only scan the filesystem, but more advanced ones have the ability to check the RAM for threats while scanning. If you’re worried about fileless malware, there are a few free antiviruses that can check the RAM for anything sneaking around in it.

Fileless Foes

While malware is more traditionally spread using an executable, it’s not always the case. Now you know how fileless malware works and how to beat it.

Is fileless malware a big concern for you? Let us know below.

Image credit: Hacker – Hacking – Lupe von Nullen und Einsen – MALWARE – blau

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Simon Batt Avatar

Read next

When Cingular chief Stan Sigman backed the original iPhone before its 2007 unveiling, he accepted terms American carriers usually refused: no logo on the device, no control over its software, no preloaded apps, and a share of monthly subscriber revenue flowing back to Apple, after signing on without seeing a prototype
Every year, roughly two billion new smartphones, laptops, and tablets ship with a key arrangement designed in the 1870s to prevent slender metal arms from colliding inside a machine that has been obsolete for decades, a piece of 19th-century mechanical engineering quietly embedded in the muscle memory of about five billion people.
Tristan Harris, Google’s former design ethicist, told the US Senate that the pull-to-refresh gesture on nearly every app works like the lever of a Las Vegas slot machine, and he has long warned that we now reach for our phones around 150 times a day without ever calling it gambling
In 1969, László Bélády and two IBM colleagues published a paging-machine anomaly showing FIFO could make four memory frames suffer ten page faults after three frames suffered nine, leaving generations of operating-systems students staring at the moment more memory became the wrong answer
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
The colour magenta does not exist anywhere in the spectrum of visible light, and your brain manufactures it on the spot whenever red and blue cones fire together, inventing a hue to fill a gap that physics never bothered to provide.
On 28 May 2009, Google demoed a product called Wave on stage at I/O for 80 minutes and got a standing ovation from developers who had no idea what they had just watched, and 15 months later the company quietly shut it down because almost nobody could explain to a friend what it was actually for
When Clair Patterson set out in 1948 to measure the age of the Earth using lead in meteorites, his samples kept coming back contaminated, and the seven-year detour he took to find the source ended with him almost single-handedly forcing leaded gasoline out of American cars by 1986.