logo

Fileless malware campaign roundup

ID: 98e74f65-ea1f-5f1e-9dcf-e28e4bd6ac13

STIX ID: report--98e74f65-ea1f-5f1e-9dcf-e28e4bd6ac13

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report examines an increase in fileless infection chains that leverage legitimate Windows utilities and document exploits to load malware directly into memory—highlighting three cases: njRat (backdoor) delivered via DOCX→RTF→VBA→PowerShell, Sodinokibi/REvil (ransomware) loaded from Base64 PowerShell in a BAT→pastebin chain, and Astaroth (credential-stealing trojan) using LNK→WMIC→XSL→Bitsadmin/Certutil/Regsvr32. The report emphasizes detection challenges, provides example IOCs (download URLs and a C2 domain), and explains how these tactics avoid disk artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.