Anatomy and Defense of LOTL Fileless Intrusions

Amol Sarwate (Director of Security Research · Cohesidi Red Lab)

BSidesSF 2026 · Day 1 · AMC Theatre 13

Overview

This technical article delves into the intricate world of Living Off The Land (LOTL) and fileless intrusions, a pervasive and increasingly dominant threat landscape in cybersecurity. Presented by Amol Sarwate, Head of Cohesity Red Lab and Director of Security Research, this talk dissects the anatomy of such attacks, offering critical insights into their exploitation methods, real-world examples, and effective defense strategies. Sarwate's team at Red Labs specializes in detonating and studying live malware, providing a foundation of practical, empirical knowledge for this presentation.

Watch on YouTube

Key moments

  1. 0:00 Introduction to fileless and living off the land
  2. 2:55 Defining fileless and living off the land (LOTL)
  3. 4:22 Initial attack vector: Clickfix vulnerabilities
  4. 6:07 Real-world examples of Clickfix attacks
  5. 8:10 Malvertisements as an attack vector

Anatomy and Defense of LOTL Fileless Intrusions

Speakers: Amol Sarwate, Head of Cohesity Red Lab, Director of Security Research

Conference: BSides SF

YouTube: https://www.youtube.com/watch?v=pn_Zy0oHYNE

Overview

This technical article delves into the intricate world of Living Off The Land (LOTL) and fileless intrusions, a pervasive and increasingly dominant threat landscape in cybersecurity. Presented by Amol Sarwate, Head of Cohesity Red Lab and Director of Security Research, this talk dissects the anatomy of such attacks, offering critical insights into their exploitation methods, real-world examples, and effective defense strategies. Sarwate's team at Red Labs specializes in detonating and studying live malware, providing a foundation of practical, empirical knowledge for this presentation.

The significance of understanding LOTL and fileless attacks cannot be overstated. According to a Bitdefender study, 84% of incidents by 2025 are projected to involve living off the land binaries, highlighting their ubiquity. Furthermore, Microsoft research indicates that 47% of initial access vectors last year were attributed to "clickfix" type vulnerabilities, often a precursor to fileless or LOTL activity. This talk is crucial for security professionals, system administrators, and anyone involved in organizational defense, as it illuminates the sophisticated techniques employed by modern adversaries and provides actionable intelligence to fortify defenses against these hard-to-detect threats.

Background

▶ Watch: Introduction to fileless and living off the land (0:00)

The evolution of malware has seen a significant shift from traditional, disk-based executables to more stealthy and evasive techniques. Sarwate briefly traces this progression, noting the commercialization of ransomware through Ransomware-as-a-Service in the last five years and the rise of supply chain attacks preceding it. These trends have paved the way for the current prominence of fileless and living off the land attacks, which often leverage realistic AI-looking deception strategies.

To establish a common understanding, Sarwate provides clear definitions:

  • Fileless: Refers to malware that operates entirely in memory, leaving no executable artifacts behind on the disk. This characteristic makes it notoriously difficult for traditional signature-based antivirus solutions to detect.
  • Living Off The Land (LOTL) / LOLBins: Describes attacks that abuse trusted, legitimate system tools and binaries already present on a target system. By utilizing these "LOLBins" (Living Off the Land Binaries), attackers can blend their malicious activities with normal user or administrative operations, making detection challenging as the tools themselves are not inherently malicious. The term "living off the land" was coined approximately eight years ago at DerbyCon, drawing an analogy to humans using existing resources rather than carrying their own.

Initial access for these sophisticated attacks largely relies on exploiting human interaction. Microsoft's research from the previous year revealed that clickfix vulnerabilities accounted for 47% of initial access, surpassing even phishing, which had long been the top vector. Clickfix attacks involve social engineering where a victim is tricked into clicking a malicious link, interacting with a social post, or opening an advertisement that presents a fake system alert (e.g., "Your Chrome is outdated, click here to fix"). The user is then guided to download or execute malicious code. Examples include deceptive browser update prompts, fake Facebook update notifications, or bogus Office 365 document fix requests.

Beyond clickfix, malvertisements represent another significant initial vector, often requiring no direct user interaction beyond an accidental click. Attackers register malicious ads on legitimate websites. When a user clicks, a JavaScript payload fingerprints their browser and installed plugins, identifying vulnerabilities. While browser vendors have improved auto-patching, outdated or vulnerable plugins, often developed by third parties without consistent updates, remain a significant attack surface. The identified vulnerability is then exploited to deploy shellcode directly into the browser or plugin's memory space.

Key Findings

▶ Watch: Defining fileless and living off the land (LOTL) (2:55)

Amol Sarwate's analysis of four distinct real-world malware samples (Asteroth, Storm 249, Cookbook, and Head Crab) revealed crucial commonalities, allowing him to construct a generalized anatomy of fileless and living off the land intrusions. These key findings highlight the sophisticated, multi-stage nature of these attacks:

  1. Fileless Initial Access: The initial compromise often avoids writing executables to disk. Common methods include LNK shortcuts that point to legitimate Windows utilities, direct PowerShell execution via encoded commands, or web-based exploits delivered through malvertisements or clickfix campaigns that drop shellcode directly into memory.
  2. In-Memory Execution: Once initial access is gained, the malware strives to operate entirely within the system's RAM. Techniques observed include DLL side-loading, where a legitimate, signed executable is tricked into loading a malicious DLL placed in a specific directory; reflective DLL injection, where a DLL is loaded directly into a process's memory without being written to disk; and process hollowing, where a legitimate process's memory space is emptied and then filled with malicious code, making the malicious activity appear as part of a trusted process.
  3. Abuse of Legitimate Binaries (LOLBins): A cornerstone of LOTL attacks is the strategic misuse of trusted, signed Windows utilities. These binaries are present on all Windows systems and are generally allowed by security software, making their malicious use difficult to detect. Key LOLBins frequently abused include:
  • PowerShell.exe: For executing malicious scripts, decoding payloads, and interacting with the system.
  • Certutil.exe: Legitimate use is certificate management, but it can decode Base64-encoded payloads using specific command-line parameters.
  • Bitsadmin.exe: Designed for background file transfers, it's abused to download malicious code from attacker-controlled servers.
  • Regsvr32.exe: Used to register COM/DCOM components, but can also load and execute arbitrary DLLs.
  • WMIC.exe: The Windows Management Instrumentation Command-line utility, used for system querying and execution.
  • Curl.exe: A common command-line tool for transferring data, used to download malicious scripts or payloads.
  1. Persistence Mechanisms: To survive system reboots or maintain access, fileless malware employs various persistence techniques that avoid traditional file system entries. These include leveraging the Windows Management Instrumentation (WMI) repository to register event handlers that execute malicious code upon specific triggers (like system reboot) or the age-old technique of adding entries to the Run registry key, ensuring execution at startup.

Sarwate emphasized the high prevalence of these attacks, citing the 84% figure for LOTL incidents and 47% for clickfix as an initial vector. A critical underlying finding is the exploitation of human trust, with 82% of attacks having a human interaction as their initial vector, and 70% of these potentially avoidable through proper user training and awareness. This highlights that despite the technical sophistication, the human element remains the most vulnerable link in the security chain.

Technical Deep Dive

▶ Watch: Initial attack vector: Clickfix vulnerabilities (4:22)

The core of Sarwate's talk involved a detailed examination of four real-world malware samples, each showcasing distinct fileless and LOTL techniques, providing a concrete understanding of their operational mechanics.

Asteroth

Asteroth malware, named after a demon known for intellect and making things disappear, epitomizes the intelligent use of legitimate Windows tools to remain invisible. Its attack chain begins with a victim receiving a malicious LNK file. When clicked, this LNK file doesn't directly execute malware but instead points to cmd.exe, which then invokes wmic.exe (Windows Management Instrumentation Command-line). wmic.exe is used to run a JavaScript, which in turn calls bitsadmin.exe. bitsadmin.exe, a legitimate utility for background file transfers, is then used to download a Base64-encoded payload.

Crucially, Asteroth stores this payload in NTFS Alternate Data Streams (ADS), often within seemingly innocuous files like desktop.ini. ADS allows data to be associated with an existing file without altering its size or being visible through standard file explorers, making it a stealthy storage method. To decode and execute this payload, Asteroth utilizes certutil.exe, a legitimate certificate management utility that possesses a command-line parameter to decode Base64. Following decoding, the malware performs process hollowing. This advanced technique involves suspending a legitimate process (e.g., regsvr32.exe), removing its original code, injecting the malicious code into its memory space, and then resuming the process. This makes the malicious activity appear as if it originates from a trusted, signed Windows application. Finally, regsvr32.exe (a utility for registering DLLs) is abused to load the decoded malicious DLLs, further blending into normal system operations.

Storm 249

Storm 249 leverages the clickfix social engineering vector, often tricking users with convincing but malicious domain names (e.g., microsoft-support-something.com). Once the user is lured, curl.exe (the command-line tool for transferring data) is used to download PowerShell code directly into memory, avoiding disk writes.

What makes Storm 249 particularly effective is its use of DLL side-loading. While fileless in its initial stages, it downloads a legitimate executable from a known vendor. This executable is deliberately chosen because it's an older version vulnerable to DLL side-loading. When a Windows executable loads a helper DLL, it follows a specific search path. If the exact path for the DLL isn't specified, Windows might first look in the current working directory. Storm 249 places its malicious DLL in this current directory, ensuring that when the trusted, legitimate executable runs, it inadvertently loads the attacker's DLL instead of the intended one. This technique is highly effective at bypassing antivirus and EDR solutions, as the primary executable is legitimate and signed, leading security products to trust its execution path.

Cookbook

Cookbook malware distinguishes itself by entirely avoiding the file system, instead hiding its malicious logic within the Windows Registry. It fragments its Base64-encoded code across multiple registry key and value pairs, preventing large, easily detectable blobs of data in any single location. For persistence, it writes an entry into the Run registry key, ensuring its execution upon system startup.

When activated, Cookbook uses legitimate PowerShell commands like Get-ItemProperty to read all the Base64-encoded segments from various registry locations. These segments are then concatenated and finally executed using Invoke-Expression. Invoke-Expression is a powerful PowerShell cmdlet that treats a string as a command or script and executes it, effectively turning the reassembled Base64 payload into live code, all without ever touching the disk.

Head Crab

Unlike the previous three examples that primarily target end-users, Head Crab focuses on servers, specifically internet-exposed RADIUS database servers. Its initial vector involves internet scanning to identify RADIUS servers with default or weak credentials. Once such a server is identified and compromised using administrative credentials, Head Crab leverages the SLAVEOF command (a legitimate Redis command for replication). By issuing SLAVEOF, the attacker instructs the compromised server to replicate data from their malicious server, effectively copying malicious shared objects and Redis extensions into the victim server's memory. These extensions are designed to hinder system administrators from detecting the intrusion. The ultimate objective of Head Crab is crypto mining, turning compromised RADIUS servers into illicit cryptocurrency generators. This example demonstrates that LOTL techniques are not limited to user workstations but are also highly effective in server environments.

Demo / Proof of Concept

▶ Watch: Real-world examples of Clickfix attacks (6:07)

While the talk did not feature a live demonstration or a hands-on proof-of-concept during the presentation, Amol Sarwate's detailed breakdown of the four real-world malware samples—Asteroth, Storm 249, Cookbook, and Head Crab—served as a robust and illustrative analysis of how fileless and living off the land techniques are executed in practice. By dissecting the attack chains, specific tools used, and evasive maneuvers for each sample, the presentation effectively "demonstrated" the anatomy of these intrusions, providing a clear technical understanding without the need for a live, potentially risky, environment. This approach allowed for a deeper technical dive into the mechanisms without the constraints of a live demo.

Defensive Implications

▶ Watch: Malvertisements as an attack vector (8:10)

Defending against fileless and LOTL intrusions requires a multi-layered strategy that combines human resilience with robust technical controls. Sarwate stresses that the human element remains paramount in preventing these attacks.

Building Human Resilience

  • User Education: Training users to identify common lures, such as "fix it" pop-ups, malicious domain names (e.g., typosquatting or using legitimate-sounding words like microsoft-support-something.com), and suspicious requests to run commands from websites, is critical. Statistics show that 82% of attacks have an initial human interaction vector, and 70% of these could be avoided with proper training.
  • Browser and System Hygiene: Organizations must enforce auto-updating of browsers and, crucially, diligent scanning and patching of browser plugins. Many plugins, especially older or less-maintained ones, can have unrestricted access to browser data and present significant vulnerabilities. Users should also be trained to report anything suspicious immediately.

Technical Controls

  • Windows Attack Surface Reduction (ASR) Rules: These rules, though not enabled by default, are powerful. Sarwate highlights rules that could have blocked malware like Asteroth and Storm 249, such as:
  • Blocking persistence through WMI event subscriptions (as legitimate programs rarely need to register WMI handlers for reboots).
  • Blocking execution of obfuscated code (which would target malware like Cookbook).

Organizations should implement ASR rules in audit mode first to monitor triggered events and then progressively move to blocking mode based on their environment.

  • Memory Protection: Ensuring fundamental memory protections are enabled is vital.
  • Data Execution Prevention (DEP): Prevents code execution from memory regions designated for data.
  • Address Space Layout Randomization (ASLR): Randomizes memory addresses, making it harder for attackers to predict locations of malicious code.
  • PowerShell Lockdown: Given PowerShell's central role in many LOTL attacks, implementing Constrained Language Mode significantly curtails its abuse potential. This mode restricts PowerShell to a safe subset of functionalities, blocking the creation of COM objects, restricting many command-line parameters, and limiting script execution, while still allowing legitimate administrative tasks.
  • Reduce Footprint and Restrict LOLBins: The core premise of LOTL is abusing existing binaries. Defenders should:
  • Remove Unnecessary Binaries: Audit systems to identify and remove LOLBins that are not essential for business operations.
  • Restrict Internet Access: For LOLBins that cannot be removed (e.g., certutil, bitsadmin, curl), restrict their ability to connect to the internet, especially to external Command and Control (C2) servers. They might be allowed to communicate internally but blocked from reaching malicious external IPs or domains.
  • Advanced Logging: Enhanced logging capabilities are crucial for detection and forensic analysis. This includes:
  • PowerShell Command Logging: Even if commands are Base64-encoded, advanced logging can often de-obfuscate them for clear-text visibility.
  • WMI Activity Logging: Monitoring for suspicious WMI event registrations or script executions can detect persistence mechanisms.
  • Task Scheduler Logging: Auditing task scheduler creations or modifications for unusual entries.
  • Open-Source Intelligence: Leverage open-source projects like the GitHub repository dedicated to listing LOLBins. This project often includes detection rules (Sigma, Yara) that can be integrated into security tools.
  • Endpoint Detection and Response (EDR): A robust EDR solution provides behavioral monitoring, which is essential for detecting fileless and LOTL attacks. EDRs perform:
  • Process Behavior Analysis: Identifying anomalous process execution chains or activities.
  • Script Execution Monitoring: Detecting suspicious PowerShell or script usage.
  • Memory Analysis: Uncovering malicious code injected into legitimate processes or operating solely in memory. Organizations should verify their EDR capabilities align with these detection requirements.

Key Takeaways

  • Dominant Threat Landscape: Fileless and Living Off The Land (LOTL) attacks are no longer niche but represent the dominant threat vector, accounting for 84% of projected incidents and 47% of initial access attempts.
  • Human Trust as Initial Vector: The primary initial access method for these sophisticated attacks increasingly relies on exploiting human trust through social engineering tactics like "clickfix" and malvertisements, highlighting the critical need for user education.
  • Abuse of Legitimate Tools: Attackers "live off the land" by abusing trusted, signed Windows binaries (LOLBins) such as PowerShell, certutil, bitsadmin, and regsvr32, making their activities blend with normal system operations and evade traditional signature-based defenses.
  • Multi-Stage Attack Anatomy: The anatomy of fileless/LOTL malware typically involves fileless initial access, in-memory execution techniques (e.g., process hollowing, DLL side-loading), the extensive use of LOLBins, and stealthy persistence mechanisms (e.g., WMI repository, registry run keys).
  • Multi-Layered Defense is Essential: Effective defense requires a combination of strong human resilience through awareness training, robust technical controls like Windows ASR rules, PowerShell lockdown, memory protections (DEP/ASLR), strict auditing, restricting LOLBin internet access, and advanced EDR solutions capable of behavioral monitoring.

About the Speaker(s)

Amol Sarwate is the Head of the Cohesity Red Lab and also serves as their Director of Security Research. His work at Red Labs involves the daily detonation and detailed study of real-world malware to understand its techniques, tactics, and nuances. This practical experience forms the foundation of his insights into advanced persistent threats and effective defense strategies.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent LOTL survey built on four real malware samples — solid practitioner content that earns its place at BSides SF. Nothing here is novel for anyone already working in detection engineering or threat research, but the case-study structure gives it more backbone than the average 'LOLBins are bad' overview talk.

Heather Calloway (CISO) — SOLID

Competent, well-organized technical survey of LOTL and fileless attack mechanics with real malware samples and a reasonable defensive checklist. Valuable for practitioners who need this grounding, but it doesn't rise above the reference level — the defensive guidance is a list, not a decision framework, and there's no engagement with why organizations persistently fail to close these gaps.

→ Top-rated talks at BSidesSF 2026

All talks from BSidesSF 2026