Fileless malware campaign roundup
ID: 98e74f65-ea1f-5f1e-9dcf-e28e4bd6ac13
STIX ID: report--98e74f65-ea1f-5f1e-9dcf-e28e4bd6ac13
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabZ report examines an increase in fileless infection chains that leverage legitimate Windows utilities and document exploits to load malware directly into memory—highlighting three cases: njRat (backdoor) delivered via DOCX→RTF→VBA→PowerShell, Sodinokibi/REvil (ransomware) loaded from Base64 PowerShell in a BAT→pastebin chain, and Astaroth (credential-stealing trojan) using LNK→WMIC→XSL→Bitsadmin/Certutil/Regsvr32. The report emphasizes detection challenges, provides example IOCs (download URLs and a C2 domain), and explains how these tactics avoid disk artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
