Skip to content
October 10, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • Non-Malware (or Fileless) Attack: five knowledge points
  • Technique

Non-Malware (or Fileless) Attack: five knowledge points

Do Son October 24, 2017 5 minutes read
Fileless attack

Since May this year, WannaCry extortion software in the global outbreak, there have been Equifax experienced large-scale data leakage incidents, etc., the network security situation is very urgent, enterprises in the investment of new policies and safety products, the pressure doubled.

However, even if the increase in security budget, there are still many companies worried that the existing technology can not keep up with the rapidly changing threat situation. Companies are particularly concerned that more and more attacks will gain access to enterprise systems, secretly infect the system without having to download malicious programs or leave obvious traces, which is the so-called “Fileless attack.”

“Fileless attack” is also known as “non-malware attacks.” The bottom line of action for this type of attack is to use the trusted software and system tools for the victim’s enterprise to avoid detection. Such attacks quickly became the primary threat to IT and security experts.

Enterprise executives should understand the following five key knowledge points:

1, “Fileless” attacks mainly use traditional endpoints

Traditionally, cyber attacks involve malware, where attackers use malware to access the victim’s computer (which typically exploits software vulnerabilities or trickers to download files) and then installs a destructive executable attack.

From the point of view of the attacker, the problem with this approach is to be easily detected by anti-virus solutions. Without malicious files, attackers can easily bypass these security solutions, and attackers simply hijack other legitimate system tools and trusted applications to engage in illegal activities.

2. A large number of “Fileless” technology for attackers to use

High-level attacks can be divided into two main phases: the initial attack phase (access to the target system) and the exploits after the exploits (the activity that the attacker enters the system).

Attackers can use the “Fileless” technology in these two stages to achieve the goal, in order to avoid the traditional, and even the next generation of machines to learn anti-virus software.

In order to obtain initial access, an attacker exploits, for example, an attacker who uses a repaired Apache Struts vulnerability to execute a malicious command in the Equifax data disclosure case. Commonly used “Fileless” technology is the use of defective applications, and the code into the normal system process, access to access, and the implementation of orders in the target device, and will not be aware of. Once the initial attack is complete, the attacker can abuse the powerful system management tools (such as PowerShell, PsExec, and WMI) to avoid detection. With legitimate use cases, attackers can hide in the “broad daylight” under the right, in the network horizontal activities, and modify the registry to maintain persistence.

3. “Fileless” attack to attack with the implementation of documents

People often misunderstand “Fileless” attacks and think that it does not involve files. However, this is not the case, such attacks will usually use the file in the initial attack phase, the biggest difference is that these files are not malicious executable files, but documents such as Microsoft Office documents.

The challenge of traditional endpoint security is that the files themselves do not have malicious features, so security scans are like useless, and these files become the perfect tool for attacking.

 

For example, an attacker may begin to trick an employee from opening a Word document in a phishing email, and the victim may have no intention of activating the macro or script, and the macro or script will then enable PowerShell. After that, the attacker will use PowerShell to directly execute the malicious code in memory, so that the attack to the “Fileless” of the road.

Because the components of such attacks are not malicious, security solutions need to be able to observe the behavior of the chain of attacks and identify when other attacks from other legitimate procedures to attack.

4. “Fileless” attacks more and more

In fact, “Fileless attack” technology has been around for some time. For example, the beginning of the 21st century there has been memory exploits: Code Red and SQL Slammer worms. However, creating and widely disseminating easy-to-use attack tools and exploit tools makes “fileless” attacks more common, especially Metasploit and PowerSploit penetration testing frameworks are vulnerable to abuse because they provide off-the-shelf “no file” To implement any attack.

Therefore, such technology is not limited to skilled hackers and national espionage organizations, ordinary cybercriminals have gradually used a large number of “Fileless” technology to attack enterprises. “SANS 2017 threat situation survey” shows that nearly one-third of the surveyed companies reported a “fileless” attack.

5. How to prevent “Fileless” attacks?

Although “Fileless” technology is good at avoiding detection, there are still ways to reduce risk.

First, companies should disable less commonly used management tools. Or at least restrict permissions and functions. Because many “fileless” technologies rely on PowerShell, businesses should consider disabling or limiting its functionality.

Similarly, disabling Office macros eliminates the most common starting point for “Fileless” attacks. Enterprises should promptly repair the operating system and applications, repair is not feasible, the enterprise should isolate these systems to prevent potential attack spread.

Enterprise IT departments should identify malicious activity and behavior on the endpoint to detect and block “Fileless” attacks. There are new endpoint solutions that can prevent “fileless” attacks in real time, and IT and security executives should study new endpoint solutions and choose the most appropriate security solution.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Tags: Fileless attack non-malware

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2026-105133CVSS 6.9
    A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2023-22894CVSS 4.9
    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2016-3081CVSS 8.1
    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-3306CVSS 10.0
    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-5477CVSS 7.5
    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2021-3199CVSS 9.8
    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-107282CVSS 9.4
    The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior...
    📅 Updated: Oct 10, 2026
  • CVE-2026-107194CVSS 9.2
    Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading...
    📅 Updated: Oct 10, 2026
  • CVE-2026-108474CVSS 9.8
    In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions
    📅 Updated: Oct 10, 2026
  • CVE-2026-106294CVSS 9.1
    Incomplete cleanup in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to...
    📅 Updated: Oct 9, 2026
  • CVE-2026-106195CVSS 9.1
    Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to...
    📅 Updated: Oct 9, 2026
  • CVE-2026-106237CVSS 9.6
    Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation...
    📅 Updated: Oct 9, 2026
  • CVE-2026-96327CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows...
    📅 Updated: Oct 9, 2026
  • CVE-2026-108261CVSS 9.3
    Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview...
    📅 Updated: Oct 9, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.