'Fileless' cyber attacks on the rise in 2018: McAfee


New Delhi, Jul 28 (IANS): Cyber-criminals are increasingly applying "fileless" attacks in 2018 that leverage trusted Windows executables to invade systems and breach corporate networks, a new report has said.

"Fileless" attacks that do''t drop malware on a victi''s system. Instead, they use tools already installed on computers or run simple scripts and shellcode in memory, often hidden in the Windows Registry.

According to global cyber security firm McAfee Labs, the "fileless" attacks are growing in 2018 as these attacks are launched through reputable executables (or memory) and are hard to detect.

"One fileless threat, CactusTorch, uses the 'DotNetToJScript' technique which loads and executes malicious .NET assemblies straight from memory," McAfee said in a statement.

"In 2018, we have seen rapid growth in the use of CactusTorch, which can execute custom shellcode on Windows systems," it added.

Both consumers and corporate users can fall victim to this threat. In corporate environments, attackers use this vector to move laterally through the network.

In McA'ee's "Q2 Threat" report, many fileless malware campaigns were discovered to leverage Microsoft PowerShell to launch attacks in memory to create a backdoor into a system -- surging 432 per cent over 2017.

"Fileless" malware takes advantage of the trust factor between security software and genuine, signed Windows applications.

  

Top Stories


Leave a Comment

Title: 'Fileless' cyber attacks on the rise in 2018: McAfee



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.