Malware is malicious software designed to intrude upon unsuspecting digital victims to steal, damage, or destroy their data.
Some examples of this are ransomware, wiperware, viruses, worms…etc. Some forms are more sophisticated than others, using varying methods of infection or evasion.
Fileless malware is one of those types that is highly evasive and quite smart – only working within a computer’s memory, leaving no physical footprint on its hard drive.
With such a method of execution, does it mean that our devices are left vulnerable? Not quite.
What is fileless malware?
The way most types of malware work is that by opening an infected attachment, you inadvertently enable the code to execute its dark magic, acting without the user’s knowledge.
Consequently, the code can replicate within different parts of the system, install key-loggers or other spyware, block access to files or apps, display malicious ads, or more. Imagine it as a regular program that’s installed on your PC, just acting against your interests.
Fileless malware is a bit different. Instead of needing to be installed on your hard drive, it works within a computer’s random-access memory (RAM), using other programs to compromise the computer. So, in a sense, it manipulates existing legitimate processes for its agenda, as opposed to running a separate standalone ‘campaign’.
But you might ask, “Alright, but I still need to download it somewhere, no?” and you’d be right, in-memory ‘fileless’ malware is still delivered through malicious links or attachments, just the execution is different.
Examples of fileless malware
A great example of fileless malware was the Astaroth malware campaign, which, as discovered by Microsoft, had been using a fileless method to deliver an infostealer through a malicious email link, which upon interaction, used legitimate Windows processes such as BITSAdmin, the Alternate Data Streams file attribute and utilities of Internet Explorer to reconstruct and load itself.
In essence, it leveraged legitimate system processes and tools to run its code without having to drop executable files on the disk.
Similarly, the Kovter malware family, as detected by ESET Research in 2018, used to store its malicious payload encrypted in the Windows registry, using fileless persistence. Likewise, the GreyEnergy APT also made sure that some of its modules only ran in memory, hindering detection.
Such malware techniques are problematic for simple antivirus or endpoint security software that works by scanning files on a system, lacking process or activity scanning capabilities. But this doesn’t mean that they cannot be detected.
Protecting against fileless threats
ESET Endpoint Security’s multilayered product features an Advanced Memory Scanner module, which, combined with our Exploit Blocker, protects against malware designed with evasiveness in mind. Additionally, thanks to two different forms of Advanced Machine Learning employed within, detections are fine-tuned to weed out false positives.

ESET Endpoint Security's multiple ESET LiveSense layers for comprehensive protection
Only memory scanning can successfully discover “in-memory” operating fileless attacks that lack persistent components in the file system, such as was the case with Astaroth and its use of the Windows toolset.
Furthermore, the ESET Host-based Intrusion Prevention System (HIPS) and its Deep Behavioural Inspection (DBI) use predefined rules to scan for and monitor suspicious behaviour related to running processes, files, and registry keys, targeting the exact methods fileless malware would use to obfuscate its activities. Hence, malware families like Kovter would find it hard to hide from ESET Endpoint Security in the Windows registry, since the memory scanner also deals with encrypted threats.
Issue-less
With cybersecurity protections stepping up to protect people against advanced threats such as fileless malware, one thing still needs to be said: Never click on any malicious links or attachments in suspicious emails.
As always, exploiting human error is the best avenue for a compromise, so stay informed by reading our ESET Blogs or WeLiveSecurity to keep ahead of the cyber threat game.
Alternatively, try our free ESET Cybersecurity Awareness Training to learn how to stay secure at all times.