May 2, 2017 By Douglas Bonderud 3 min read

When it comes to malware, one thing is certain: Attackers don’t rely on the same trick for very long. It’s always a race to outsmart, outperform and outmaneuver even the best endpoint tools.

Dark Reading noted attackers are pulling ahead of security teams. Most file-based malware is undetectable by antivirus tools, even as fileless attacks completely skirt this kind of security. Overwhelmed and underequipped, have endpoint tools finally reached their end of life?

The Newest Threat on the Block?

The newest threat on the malware market take the form of fileless attacks, which exploit in-memory vulnerabilities, PowerShell scripts or Office macros to infect target computers and entirely avoid antivirus systems.

Also called nonmalware attacks because they don’t require any external files to begin the infection process, this threat vector has been quietly gaining ground. Security firm and IBM partner Carbon Black explained that 64 percent of security researchers said they’ve seen an increase in nonmalware attacks since the beginning of 2016.

More worrisome? Ninety-three percent of those surveyed said that “nonmalware attacks pose more of a business risk than commodity malware attacks.”

File-based attacks, meanwhile, are also finding ways to avoid detection tools and compromise corporate endpoints. Part of the problem stems from malware reporting: Only half of all file-based attack details have been submitted to malware repositories, and just 20 percent of those attacks were uploaded to antivirus engines, SentinelOne reported. In other words, companies are effectively flying blind when it comes to both fileless and file-based malware.

Going Inside File-Based Attacks

While the solution to combating file-based attacks is relatively simple — companies need to freely share threat data, while antivirus providers need to increase both the uptake of malware signatures and antivirus update frequency — combating fileless malware is more challenging.

To understand why, it’s helpful to examine how these attacks work. Typical modes of infection include phishing emails with malicious attachments or compromised websites that prompt users to click on infected links. Once inside the endpoint, these attacks run approved processes to execute commands and begin the download of malware or rootkit packages.

Given the inherently privileged nature of PowerShell and Windows Management Instrumentation (WMI), cybercriminal actions don’t register as system threats, and security professionals are left in the dark. It’s no surprise, then, that fileless attacks are on the rise. Ars Technica reported that more than 140 bank networks have been infected with in-memory malware over the past few months, while The Register detailed a macro-based attack targeting Israeli organizations.

Fighting Fileless Attacks With Endpoint Security

So how do companies fight back against fileless defense failures? First is the recognition that fileless attacks are the likely future of malware — threat actors won’t risk traceable files when they can infect with virtually no trace.

Next is the evolving role of endpoint security. While better information sharing can help limit the impact of file-based malware, fileless infections will always fly under the radar. As a result, the most effective defense tactic lies with network traffic. Despite their lightweight packaging and sneaky use of system-approved processes, fileless attacks still generate observable — and odd — network traffic.

Threatpost suggested that companies start by disabling PowerShell for networks, then closely monitoring outbound traffic and tracing it back to any applications making the request. This can help spot outliers: For example, if Windows Notepad or Calculator are suddenly making network requests, chances are something isn’t right.

Companies now face the double threat of file-based and fileless malware. Combating both means evolving endpoint protection to include better information sharing for file-based threats and increased traffic oversight to help fight fileless foes.

More from

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Testing the limits of generative AI: How red teaming exposes vulnerabilities in AI models

4 min read - With generative artificial intelligence (gen AI) on the frontlines of information security, red teams play an essential role in identifying vulnerabilities that others can overlook.With the average cost of a data breach reaching an all-time high of $4.88 million in 2024, businesses need to know exactly where their vulnerabilities lie. Given the remarkable pace at which they’re adopting gen AI, there’s a good chance that some of those vulnerabilities lie in AI models themselves — or the data used to…

FBI, CISA issue warning for cross Apple-Android texting

3 min read - CISA and the FBI recently released a joint statement that the People's Republic of China (PRC) is targeting commercial telecommunications infrastructure as part of a significant cyber espionage campaign. As a result, the agencies released a joint guide, Enhanced Visibility and Hardening Guidance for Communications Infrastructure, with best practices organizations and agencies should adopt to protect against this espionage threat. According to the statement, PRC-affiliated actors compromised networks at multiple telecommunication companies. They stole customer call records data as well…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today