Fileless Malware on the Rise, Traditional Defenses Failing

An alarming majority of malware (75 percent) is going undetected by “traditional malware solutions,” according to a new report. And nearly three-quarters of threats detected in the last quarter were zero-day malware — an all-time high.

The Internet Security Report for Q1 2021 from WatchGuard Technologies found that malicious scripts are delivering fileless malware in the form of an XML external entity. The most widespread was XML.JSLoader, which made the top 10 for the first time in the first quarter of 2021. According to researchers: “The sample WatchGuard identified uses an XML external entity (XXE) attack to open a shell to run commands to bypass the local PowerShell execution policy and runs in a non-interactive way, hidden from the actual user or victim. This is another example of the rising prevalence of fileless malware and the need for advanced endpoint detection and response capabilities.”

A ransomware loader called Zmutzy made the top 2 in Q1. It manifests as a disguised e-mail attachment. According to the researchers: “Associated with Nibiru ransomware specifically, victims encounter this threat as a zipped file attachment to an e-mail or a download from a malicious website. Running the zip file downloads an executable, which to the victim appears to be a legitimate PDF. Attackers used a comma instead of a period in the file name and a manually adjusted icon to pass the malicious zip file off as a PDF. This type of attack highlights the importance of phishing education and training, as well as implementing back-up solutions in the event that a variant like this unleashes a ransomware infection.”

The report highlighted a number of other trends in malware and network attacks:

  • Half of the top 10 malware families by volume were new to the top 10, including Ursu, Trojan.IFrame, XML.JSLoader, Zmutzy, and Zum.Androm;

  • Encrypted connections saw less zero-day malware (60.3 percent) than the overall average (74 percent);

  • Network attacks reached a three-year high during the first quarter, at 4.2 million Intrusion Prevention Service (IPS) hits on Firebox appliances;

  • More than 5 million malicious domains were blocked by DNSWatch in the quarter, a 281 percent increase over Q4 2020; and

  • Exploits against ProxyLogin Exchange Server flaws increased 1,600 percent.

A complete report and executive summary is available on the WatchGuard site, as well as an infographic with highlights from the report.

About the Author

David Nagel is the former editorial director of 1105 Media's Education Group and editor-in-chief of THE Journal, STEAM Universe, and Spaces4Learning. A 30-year publishing veteran, Nagel has led or contributed to dozens of technology, art, marketing, media, and business publications.

He can be reached at [email protected]. You can also connect with him on LinkedIn at https://www.linkedin.com/in/davidrnagel/ .


Featured

  • handshake where one hand is human and the other is composed of glowing circuits

    Western Governors University Joins Open edX as a Mission-Aligned Organization

    Western Governors University is the first organization to join the Open edX project as a "mission-aligned organization" (MAO), a new category of institution-level partnership supporting development of the Open edX open source online learning platform.

  • glowing crystal ball with a simplified university building inside, surrounded by seamlessly blended holographic symbols of binary code, a bar graph, database icons, and a cloud, against a gradient blue and white background with softly merging circuit patterns

    3 Areas Where AI Will Impact Higher Ed Most in 2025

    What should colleges and universities expect from the evolving landscape of artificial intelligence in the coming year? Here's what the experts told us.

  • illustration of a football stadium with helmet on the left and laptop with ed tech icons on the right

    The 2025 NFL Draft and Ed Tech Selection: A Strategic Parallel

    In the fast-evolving landscape of collegiate football, the NFL, and higher education, one might not immediately draw connections between the 2025 NFL Draft and the selection of proper educational technology for a college campus. However, upon closer examination, both processes share striking similarities: a rigorous assessment of needs, long-term strategic impact, talent or tool evaluation, financial considerations, and adaptability to a dynamic future.

  • Stylized illustration showing cybersecurity elements like shields, padlocks, and secure cloud icons on a neutral, minimalist digital background

    Microsoft Announces Security Advancements

    Microsoft has announced major security advancements across its product portfolio and practices. The work is part of its Secure Future Initiative (SFI), a multiyear cybersecurity transformation the company calls the largest engineering project in company history.