You are viewing a single comment's thread.

view the rest of the comments →

bezzy ago

If malare is only in RAM then a simple reboot wipes it. Click farming malware is mostly used to generate ad revenue.

senpaithatignoresyou ago

Not on the ram. This was also on a unix machine, windows 7 and 10 machines too.

bezzy ago

Fileless means in RAM. There is no other place for data to be. Either it's on disk and therefore there are files or it is not and then it's in RAM. If data is not written to disk and does not exist in RAM, then where is it? In the cache? Search fileless malware. It's all about existing in ram and leveraging something like PS. The only way to achieve persistence across reboots is to write to a disk, at which point it isn't truly fileless.

WarGy ago

It could be in the CPU cache, couldn't it? There's also been a few cases of malware written into the BIOS flash memory.

bezzy ago

Perhaps, I don't know enough about CPUs. At any rate that would be a very tiny virus. If something is written to BIOS then it still is not fileless.