Fileless Malware: The Attack That Leaves Nothing for Antivirus to Find

Ulises Paiz

Ulises Paiz, Founder of Ghosxt, has 10+ years in IT infrastructure and cybersecurity, an Active Top Secret Clearance, and 9 certifications including CySA+, Security+, and AZ-104. Before founding Ghosxt, he served as a Senior Solutions Consultant for the DoD and built security programs for 40+ Central Coast businesses. More about Ulises →

Ask most small business owners what antivirus does, and they'll describe something close to the truth: it scans files and blocks the bad ones. That mental model has held up for two decades because it used to be accurate. It isn't anymore. A growing share of intrusions never install a traditional program at all. Instead, they hijack tools that were already sitting on the computer the whole time, tools that Windows itself trusts completely, and use them to do everything a piece of malware would normally do: move around the network, steal credentials, and open the door for ransomware. Nothing gets written to disk for a scanner to catch, because nothing new needs to exist. That's the entire point.

How fileless and living-off-the-land attacks actually work

An attacker gets an initial foothold the same way they always do, a phishing email, a malicious attachment, or a stolen password, but the next step looks nothing like classic malware. Instead of dropping an executable file, they open PowerShell, a legitimate administrative tool built into every copy of Windows, and run commands directly in memory. Or they use Windows Management Instrumentation (WMI) to move between computers on the network. Or they hide a malicious macro inside a Word or Excel document that, once enabled, launches these built-in tools rather than a separate program. Security teams call this "living off the land" because the attacker survives entirely on what's already there, never bringing in anything a file scanner would recognize as foreign. By the time anything visible happens, like a ransomware note or stolen data showing up for sale, the attacker may have already been living inside the network using nothing but trusted, everyday tools for days or weeks.

Why this matters for a small business

  • Traditional antivirus genuinely can't see it. Signature-based scanning looks for known malicious files. When the attack never creates one, there's nothing to match against a signature database.
  • It doesn't need admin rights to start doing damage. PowerShell and WMI run under whatever account is already logged in, so a single compromised employee login is often enough to begin moving through the network.
  • It's built to survive a reboot and a quick look. Because there's no suspicious file sitting in a folder, a quick manual check of "what's installed" turns up nothing, which is exactly why these attacks can persist far longer than file-based malware before anyone notices.
  • It's often the quiet middle step before ransomware. Attackers frequently use living-off-the-land techniques to explore a network and steal credentials for days before ever deploying the ransomware payload that finally gets noticed.

What actually stops it

  • Deploy EDR, not just antivirus, since endpoint detection and response watches for suspicious behavior and unusual command patterns instead of only matching known bad files.
  • Turn on PowerShell logging and constrained language mode so unusual scripts are recorded and administrative commands are restricted for accounts that shouldn't need them.
  • Block Office macros from internet-sourced documents by default, closing one of the most common ways this style of attack gets its first foothold.
  • Enforce least-privilege accounts, so a compromised everyday login can't launch WMI or PowerShell commands with administrative reach across the network.
  • Keep centralized, tamper-resistant logging so an attacker clearing local event logs on one machine doesn't erase the only record of what happened.

Where this fits

FAQs about fileless malware

What is fileless malware?

Fileless malware is an attack that runs entirely in a computer's memory instead of installing a program on the hard drive. Because it never writes a malicious file to disk, traditional antivirus, which mostly scans files, has nothing to catch. The attack typically rides inside legitimate, already-trusted tools built into Windows.

What is a living-off-the-land attack?

A living-off-the-land (LOTL) attack uses legitimate administrative tools already installed on a computer, such as PowerShell, Windows Management Instrumentation, or macro-enabled Office documents, to carry out an attack instead of installing new malicious software. Because these tools are trusted parts of Windows, security software that only flags known-bad programs tends to let the activity through.

How does a small business defend against fileless malware?

Traditional antivirus alone isn't enough because it looks for known bad files. A small business needs endpoint detection and response (EDR) that watches for suspicious behavior, PowerShell logging and constrained language mode turned on, Office macros blocked from the internet by default, and least-privilege accounts so a compromised login can't run administrative tools in the first place.

Not sure if your antivirus would even catch this?

30 minutes with a DoD-cleared engineer. We'll check whether your endpoints have behavior-based detection in place, confirm PowerShell logging is on, and make sure a single compromised login can't move freely across your network.

Book your free security assessment
Call (831) 204-0501 Book free assessment