logo

Analyzing a Fileless Malware Loader

ID: 417b0db0-5474-515b-b00b-3b9c58461fdb

STIX ID: report--417b0db0-5474-515b-b00b-3b9c58461fdb

Feed Name: WatchGuard Secplicity Blog

Threat Score
75/100

Date Published: 2020-10-15

Date Updated: 2026-05-01

Author: The Editor

...
...

WatchGuard Threat Lab analyzed and stopped a sophisticated fileless downloader that executed entirely in memory via JavaScript-triggered PowerShell using ReflectivePEInjection; the attack chain included kernel and Win32k privilege-escalation exploits (CVE-2020-1054, CVE-2019-1458, CVE-2019-0808) and a Chrome sandbox escape (CVE-2019-5786). The report documents domains and MD5s tied to the campaign, explains the in-memory, evasive nature of the attack, and recommends strong EDR/EPP, DNS filtering, and IPS to detect and block similar intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.