Fileless Malware: What Is It and How Can You Protect Yourself From It?

Fileless Malware: What Is It and How Can You Protect Yourself From It? Featured Image

When you think of a virus infecting a system, you may imagine a scenario where someone opens an infected executable file on their PC. This then plants the malware on the system which can then steal information, commence a cryptojacking attack, or do damage to the filesystem. With antivirus being a key part of people’s computers these days, it’s been tricky to get this sort of attack to play out. Recently, we’ve seen a spike in an interesting method of spreading malware – by not using files at all!

Also read: Triada Malware Preinstalled on Low-Cost Android Phones – Here’s How to Beat It

What Is “Fileless Malware?”

fileless-malware-folder

Of course, the malware isn’t totally fileless — it has to come from somewhere after all! The idea here is that the malware works without needing a file on the computer’s filesystem. That way it can operate without needing a “home base” that will give its presence away.

If you think about how a traditional antivirus works, you can see why fileless malware takes this interesting path. An antivirus will check all of the files on a computer’s filesystem for anything that might have been infected. Of course, if the malware hasn’t left any traces on the filesystem itself, there’s no way the scanner can pick up on it and remove it. This is fileless malware’s greatest strength; it’s stealthier than other traditional means.

Where Does It Live?

So if the malware isn’t residing on your computer’s filesystem, where is it being stored? The idea behind fileless malware is that it can operate entirely within the PC’s RAM. The RAM is used to store software while it’s running, so malware can sneak into the RAM where it can do its work while skirting detection. It may get into the system using a vulnerability in existing software, such as through a browser plugin, a hole in the operating system’s defenses, or macros in programs such as Word.

fileless-malware-ram

Living in the RAM means that the malware goes undetected from antiviruses that check the filesystems, but it also comes with a disadvantage. Filesystem-based malware persists when the PC is shut down because hard drives remember data after the computer has been turned off. The RAM, however, gets wiped on shutdown, meaning any RAM-based malware inside of it also perishes. As such, fileless malware is designed to be stealthy and quick so it can perform its job before the PC gets turned off.

How to Avoid It

So now that you know what fileless malware is, how do you avoid being hit by it?

Avoid Untrusted Macros

Try not to install any macros that aren’t from a reputable source. There’s a chance that macros on shady sites will be programmed to take advantage of security holes in the software you’re running the macro in. Only use macros from good, trusted sources.

Keep Software Up to Date

Because fileless macros need a security hole to breach a system, it’s a good idea to keep your software updated with the latest security patches. This includes your operating system which can have native processes hijacked by fileless malware.

Also read: The “Troubleshooter” Malware Scam and How to Fix It

Use a Good Antivirus

fileless-malware-antivirus

A basic antivirus will only scan the filesystem, but more advanced ones have the ability to check the RAM for threats while scanning. If you’re worried about fileless malware, there are a few free antiviruses that can check the RAM for anything sneaking around in it.

Fileless Foes

While malware is more traditionally spread using an executable, it’s not always the case. Now you know how fileless malware works and how to beat it.

Is fileless malware a big concern for you? Let us know below.

Image credit: Hacker – Hacking – Lupe von Nullen und Einsen – MALWARE – blau

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Simon Batt Avatar

Read next

When Apple shipped iOS 12 in June 2018, a small feature called Screen Time slipped onto every iPhone with a counter nobody had quite prepared for — a tally of pickups — and within a day Tim Cook was telling CNN the number of times he picked up his own phone was simply too many
When NASA lost contact with the IMAGE satellite in 2005, an amateur radio operator in Canada named Scott Tilley picked up its signal in January 2018 while hunting for a classified spy satellite, and the spacecraft turned out to be still spinning, still powered, and still trying to phone home after 13 years of silence.
The original iPhone Steve Jobs unveiled in January 2007 could not record video, could not copy and paste text, could not run a single third-party app, and could only reach the internet over 2G — and Jobs spent ninety minutes on stage at Macworld arguing, one missing feature at a time, that every absence was actually a design decision.
In 1965, Joe Sutter’s Boeing team began shaping the 747 around a future they thought would belong to supersonic jets, lifting the cockpit onto a hump so the nose could open for cargo once the giant subsonic passenger plane had outlived its brief moment
Apple’s original 1984 Macintosh keyboard had no arrow keys, no function keys, and no numeric pad because Steve Jobs wanted users to reach for the mouse first. Then Apple quietly sold the missing keys as an accessory.
When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
Masahiro Hara and Denso engineers built the QR code in 1994 to help Toyota suppliers scan car parts from any angle, then kept the patent open until phone cameras and a 2020 pandemic turned the factory square into a daily ritual on restaurant tables
In 1965, Mary Allen Wilkes wrote LAP6 for the LINC computer from her parents’ Baltimore home, testing an interactive operating system on a 250-pound machine in the living room and becoming the first known person to use a personal computer at home, twelve years before the Apple II reached buyers