Skip to content
Threat Feed

Tag

Fileless

6 briefs RSS
high threat

Abuse of TinyCC Compiler for Shellcode Execution

The Lotus Blossom Chrysalis backdoor campaign leverages the Tiny C Compiler (TinyCC) to execute shellcode in memory by masquerading the compiler binary as a system process.

Lotus Blossom windows execution defense-evasion fileless
1r 3t
high advisory

Scheduled Task Execution of Encoded PowerShell Registry Payloads

Adversaries utilize the Windows Task Scheduler to execute obfuscated PowerShell commands retrieved from Registry keys to maintain persistence and execute payloads.

persistence execution fileless
1r 2t
high advisory

Fileless Multi-Stage Remcos RAT via Phishing

A fileless multi-stage Remcos RAT is delivered via phishing, achieving memory-resident execution, but specific technical details are not provided in this brief.

remcos rat fileless phishing
2r 4t
high threat

Lazarus Group Macloader Malware Analysis and Repurposing

The Lazarus group's macloader malware (OSX.AppleJeus.C) uses a launch daemon for persistence and executes downloaded payloads directly from memory, communicating with a C2 server to retrieve second-stage payloads, posing a significant threat due to its fileless execution and potential for repurposing.

macOS Lazarus Group +4 lazarus-group malware fileless applejeus
2r 2t 1i
high advisory

MSHTA Executing Inline HTA Script

Detection of mshta.exe executing with inline script protocols like JavaScript or VBScript, often used for malicious script execution and defense evasion.

Windows mshta fileless defense-evasion
2r 1t
high threat

Lazarus Group's macOS 'Fileless' Implant

The Lazarus APT group is distributing a trojanized macOS application named UnionCryptoTrader.dmg that installs a launch daemon for persistence, downloads and executes secondary payloads in-memory, and communicates with the command and control server unioncrypto.vip.

macos Lazarus Group +4 lazarus fileless trojan
3r 3t 3i