Skip to content
The Cyber Security Place

Threats

Malware in 2026: most intrusions no longer involve a file

The industry spent thirty years learning to find malicious files, and the attackers stopped using them. What replaced the file is software that was already installed, running under credentials that are genuinely valid.

Last reviewed August 25, 2026

Roughly 79% of initial-access attacks are now malware-free, using stolen credentials and tools already present on the machine. Where code does run, about 70% of serious incidents involve fileless execution in memory, and legitimate system binaries were implicated in around 86% of critical incidents. Infostealers are the most active category: detections up about 220% since 2023, with more than 155,000 distinct samples seen in early 2026. Close to 90% of samples use some form of polymorphism, which defeats signatures but not behaviour. Subscription malware-as-a-service is now the normal distribution model, and a single loader family accounted for close to half of malware-related incidents in a recent year of response work. The most useful single control is restricting which accounts may invoke ascript interpreter, because that is where step two of almost every chain lands.

What does the word still mean?

Less than it used to, and the gap between the word and the thing causes real misallocation. The mental picture most people carry is a malicious program: a file that arrives, gets saved, and runs. Everything the security industry built for three decades assumed that picture, and it assumed correctly for most of that time.

Four intrusions in five now involve no such file. The attacker signs in with credentials that work, uses administrative tools that shipped with the operating system, and accomplishes what a purpose-built program would have done — without introducing anything that could be scanned, quarantined or submitted to a vendor. There is no sample to analyse because no sample exists.

Where code does run, it increasingly runs in memory and never touches storage. Fileless execution is now the majority pattern among serious incidents, which creates a second problem beyond detection: it destroys its own evidence. A machine rebooted during triage has lost the only copy of what was running, and responders arrive to an estate that looks clean and was not.

The useful reframing is to stop asking what got installed and start asking what ran, under whose account, and what it reached. That question survives all three cases — file, memory, no code at all — and it is the one that current detection is actually built to answer.

What is left on the disk

Intrusions split by what a scanner examining files would find. The proportions are the argument: the case that tooling was designed around is now the smallest one.

79%malware-freeMalware-free intrusionabout 79 per cent of intrusionsIn-memory / filelessabout 15 per cent of intrusionsConventional file on diskabout 6 per cent of intrusions
Proportions rounded from published incident-response research. The categories overlap at the edges — an intrusion can begin malware-free and later run something in memory — so the split describes the dominant characteristic.

Why is a signed system tool the attacker's best weapon?

Because every defensive assumption about it is favourable. It is signed by the operating system vendor. It is present on every machine. It is used constantly by legitimate administration. And blocking it outright breaks things that people need, which means the safe default everywhere is to allow it.

The technique is old enough to have been named before it mattered. This section was carrying a piece titled precisely "Stealing Data By Living Off The Land" in September 2015, at a point when it was a clever minority approach worth writing about. Legitimate binaries are now implicated in something like six critical incidents in seven.

What changed was not the technique but the economics of the alternative. Writing a custom implant that evades modern endpoint tooling is genuinely difficult and expensive. Using the remote administration utility the organisation already deployed costs nothing, works everywhere, and generates telemetry that looks like an administrator doing their job — because on any given day it usually is.

Defending against it means giving up on the question of whether a program is malicious, because the program is not. What remains is context: this account, this machine, this hour, this destination. That is harder, it produces more false positives, and it is the only thing that works — which is a considerably less satisfying answer than a product with a detection rate on the box.

Six places to break the chain

An intrusion is a sequence, and a sequence fails if any link fails. Step through the stages below — each one carries what happens and the control that stops it there.

Worked exampleSix places to break the chain

  1. Delivery

    A link, an attachment or a compromised update reaches somebody. Increasingly there is no attachment at all — a link to a document on a legitimate file-sharing service passes every reputation check, because the service is real and the account paying for it was stolen last week.

    What breaks it hereBlocking the category of file rather than the file itself. Most organisations have no business receiving a script or an archive containing one, and refusing the type outright removes an entire delivery route without needing to detect anything.

  2. Execution

    Something already on the machine runs the first instruction. Not a downloaded executable — a scripting host, a document macro, a signed utility that ships with the operating system. There is nothing malicious on disk to find, because nothing malicious was written to disk.

    What breaks it hereRestricting which interpreters ordinary user accounts may invoke at all. Finance does not need to run scripts from a document, and the number of people in any organisation who genuinely do is small enough to enumerate.

  3. Retrieval

    The first stage is tiny and does one job: fetch the real payload. Splitting it this way means the thing that arrived was too small and too generic to look like anything, and the part that matters never sat still long enough to be sampled.

    What breaks it hereEgress control and DNS filtering. The payload has to come from somewhere, and a workstation that can only reach the destinations it needs is a workstation where this step fails regardless of what got executed.

  4. Persistence

    A scheduled task, a registry entry, a service, an addition to a startup folder — something that survives the reboot. This is the step most likely to be caught, because it changes the machine in ways that are enumerable and rarely change otherwise.

    What breaks it hereAlerting on the change rather than on the content. New scheduled tasks and new services are low-volume events on a managed estate, and reviewing them is a tractable amount of work compared with reviewing everything else.

  5. Collection

    Browser credential stores, saved session cookies, cloud tokens, anything that authenticates without a password. This is where most modern malware stops: it is not looking for your documents, it is looking for the keys to accounts elsewhere.

    What breaks it herePhishing-resistant authentication, which makes a stolen credential worthless, and short session lifetimes, which make a stolen cookie expire before it is used.

  6. Handoff

    The access is sold or escalated. Very often the operator who got in is not the one who will act on it: the credential goes to a marketplace, and something else arrives weeks later using it. The gap between infection and consequence is why the two get investigated as unrelated events.

    What breaks it hereNothing, by this point. Everything on this list happens earlier for a reason, and an organisation that only detects at this stage is reading about itself in someone else's incident report.

The point of the sequence is that there are six of them. A programme built entirely around stopping step two is one control away from failing completely; one that touches four of the six survives being wrong about any single link.

The reason to present this as a sequence rather than a list of controls is that it changes what a gap means. A programme concentrated entirely on one stage is one failure away from nothing; a programme touching four of the six survives being wrong about any single link, which is a more realistic goal than being right about all of them.

It also reorders the spending. Steps three and four — where the payload is fetched and where persistence is written — are the cheapest places to intervene and consistently the least funded, because neither produces a dashboard anyone wants to demonstrate.

The category that overtook everything else

Infostealers are now the most active kind of malware by a wide margin, and what they take is credentials that frequently belong to nobody, with detections up roughly threefold since 2023 and well over a hundred and fifty thousand distinct samples observed in a single quarter. They are also the least dramatic: no encryption, no ransom note, no visible damage. That is precisely why they work.

The job is narrow. Read the browser credential store, collect saved session cookies, take any cloud or application tokens lying around, send the lot to a collection point, and frequently delete itself. The whole operation takes minutes and produces no ongoing activity for anyone to notice.

Session cookies are the part that people underestimate. A password is one factor and can be changed; a session cookie is proof that authentication already completed, and replaying it skips both the password and the second factor entirely. An organisation that responds to a stealer infection by resetting passwords has addressed the least valuable thing that was taken.

The timing also breaks conventional response. Containment procedures assume an intruder who is present and can be cut off; here the malware finished before the alert was triaged, and what remains is not a machine to isolate but a set of credentials in circulation. The correct response is closer to a breach notification exercise than to an incident containment one, and organisations routinely reach for the wrong playbook.

So is endpoint protection still worth buying?

Yes, and for different reasons than the ones on the datasheet. The volume of commodity attack that never reaches a human because a scanner removed it is enormous and invisible, and an organisation that removed its endpoint tooling would discover the scale of that within days. The question is not whether to have it. It is what to weight when choosing and configuring it.

Detection-rate comparisons measure the shrinking part. They are run against collections of files, which is the one category current tooling was always going to handle, and they say nothing about the four intrusions in five that involve no file at all. A product that scores marginally better on a sample set and offers weaker visibility into process relationships is the worse purchase, and the tables cannot show that.

The features that matter are unglamorous. Whether the tool records what started what, and keeps that history long enough to investigate something noticed a week later. Whether it can block a relationship — this document reader may not start that interpreter — rather than only a known-bad file. Whether its telemetry can be queried across the estate, so that finding one thing lets you look for it everywhere in an afternoon.

And whether anybody reads it, which is the part no procurement process assesses. A capable tool in an organisation with nobody to act on its alerts produces a detailed record of an incident that will be read afterwards. That is worth something, and it is not what was bought.

Bought by subscription, like everything else

Almost nothing deployed today was written by the person deploying it. Loaders, stealers and remote access tools are sold as subscriptions with version numbers, support channels and update schedules, on marketplaces that behave like any other software channel. One loader family accounted for something close to half of all malware-related incidents in a recent year of response engagements.

This has two consequences that matter defensively. The first is that the skill floor has collapsed: operating a capable toolkit now requires a payment method rather than an education, which broadens the population of attackers far beyond anyone tracking named groups.

The second is that attribution has become close to useless for defence. The same loader appears in an opportunistic smash-and-grab and in a patient intrusion, because both parties are customers of the same supplier. Knowing which family you are looking at says something about the tooling and almost nothing about who is on the other end or what they intend.

It also explains why polymorphism became universal. When distribution is a service, generating a fresh variant per customer per campaign is a feature the supplier provides automatically. Nine samples in ten now change their code to defeat signatures, which costs the attacker nothing and retires an entire generation of defensive technology.

What should detection actually look for?

Behaviour and relationships, because identity is what remains constant when the code does not. Four questions cover most of the ground, and none of them requires knowing what a file contains.

Did a scripting host start from something that never starts one? A document reader spawning a command interpreter is rare, legitimate occasionally, and worth interrupting every time. This single relationship catches a large share of step two across otherwise unrelated intrusions.

Did something new arrange to survive a reboot? New scheduled tasks and new services are low-volume on a managed estate. The review is tractable and the signal is strong, which is an unusual combination worth exploiting.

Did a workstation talk to somewhere it has no reason to reach? Payload retrieval and credential exfiltration both need a destination, and the set of destinations an accounts payable machine legitimately needs is small enough to describe.

Is an account doing something it has never done? The malware-free case produces no code to examine at all, and this is the only question that reaches it. It is also the hardest to operate, which is why it tends to be the last thing organisations build and the first thing they needed.

All four share a property worth naming, because it explains why they get deferred. None of them produces a verdict. A signature match says "this is bad" and closes itself; a relationship alert says "this is unusual" and hands someone a decision. That is more work per alert and it is the only kind of alert that reaches the majority of current intrusions, which makes the staffing question inseparable from the tooling one.

How the payload stopped being the point

The direction of travel has been visible in the reporting for a decade, arriving in steps rather than as a break. The mid-decade preoccupation was banking trojans: purpose-built programs that stole money directly, of the kind this section was covering as a distinct category by August 2015. The value was in the program, and so was the arms race.

Fileless execution arrived next as a specialist technique with a memorable early example — banks compromised without a file on disk, in early 2017. What made that notable then is now unremarkable, which is the clearest possible measure of how far the baseline moved.

Mirai, from late 2016 demonstrated something different again: that the valuable asset was access at scale rather than sophistication, assembled from devices nobody was defending. And Emotet's shift to a delivery service completed the separation: the successful business was getting in and selling that on, leaving the profitable part to somebody else.

Read together the trajectory is consistent. Value migrated out of the program and into the access, and once access became the product there was no reason to keep carrying a program that could be detected.

One consequence of that shift lands on how organisations read their own history. An infostealer alert dismissed in 2024 as a low-severity commodity detection, and an intrusion investigated eighteen months later, are frequently the same event separated by a sale. Treating the first as noise because nothing appeared to happen is reasonable given what was visible at the time, and wrong — which is an argument for retaining telemetry long enough to connect the two rather than for blaming whoever triaged it.

Cleaning up after something that left no file

The instinct to reimage is sound and incomplete. Rebuilding the machine removes whatever was running on it and does nothing about the credentials that left, which in most current infections is the entire point of the attack.

Three things have to happen alongside the rebuild. Every credential the machine held must be treated as known to somebody else — not just the user's password, but saved application logins, API keys in configuration files, and anything cached by a browser profile. Sessions have to be revoked explicitly, because a cookie taken yesterday keeps working after today's password change. And the persistence mechanisms need enumerating even on a machine being rebuilt, because what was found there is what to search for everywhere else.

There is a scoping question that organisations answer too narrowly under time pressure. If the account was a domain administrator, the incident is not one workstation. If the browser profile was signed into a corporate identity provider, the exposure includes every application behind it. Deciding the blast radius by where the alert fired is how a single infection turns into a second incident a month later.

The reboot deserves one final caution. It clears in-memory code and destroys the evidence of what that code was, so a machine rebooted during triage cannot be analysed afterwards. Capture memory before restarting anything, or accept that the question of what happened will stay open permanently.

Finally, decide in advance what "clean" means for your organisation and write it down, because under pressure the definition drifts towards whatever can be achieved by lunchtime. A machine is not clean because a scan came back empty — the scan was looking for the thing that was least likely to be there. It is clean when it has been rebuilt from a known image, its credentials have been rotated, its sessions revoked, and the persistence mechanisms found on it have been searched for across every other machine that account could reach. That list takes considerably longer than running a scan, and it is the only version of the word that survives contact with a second incident three weeks later.

Write that definition while nothing is on fire, agree it with whoever signs off the downtime it implies, and keep it somewhere reachable when the file server is not. Every organisation that has argued about this during an incident has argued about it at the worst possible moment, with the people who could settle it asleep.

Common questions

What is malware in 2026?

Increasingly, not a file. Most intrusions now use credentials and tools already present on the machine, and where code does run it usually runs in memory. The word still describes the outcome, but the mental image of a virus sitting in a folder describes a shrinking minority of cases.

What does living off the land mean?

Using software that is already installed and legitimately signed — scripting hosts, management utilities, remote administration tools — to do what an attacker would otherwise need their own program for. Nothing malicious is introduced, so there is nothing malicious to detect.

Does antivirus still do anything?

Yes, against the portion of the problem that involves a file, which is now the smallest portion. Modern endpoint tools earn their keep on behaviour rather than signatures, and an organisation buying on detection-rate tables is measuring the part that matters least.

What is an infostealer?

Malware whose only job is to harvest credentials, session cookies and tokens and send them somewhere. It is the most common category by a wide margin, and it runs briefly and leaves — which means the infection is often over before anyone would have noticed it.

Why do stolen session cookies matter so much?

Because a session cookie is proof that authentication already happened. Replaying one skips the password and the second factor entirely, which is why an infostealer that never touches your password can still result in somebody reading your mail.

What is fileless malware?

Code that executes without being written to disk — a script fetched and run in memory, or a payload injected into a running process. It defeats scanning that examines files, and it disappears on reboot, which also destroys the evidence.

What is malware-as-a-service?

The commercial arrangement behind most of what is deployed: subscription access to a loader, a stealer or a remote access tool, with support and updates. It separates the person who builds the software from the person who uses it, and lowers the skill required to almost nothing.

Why does the same infection get sold on?

Because access and exploitation are different businesses. An operator who compromises a machine often sells the credentials rather than acting on them, so the consequence arrives weeks later from a different party — which is why the infection and the incident get investigated as unrelated events.

Does polymorphism defeat detection?

It defeats signatures, which is why almost all current samples use it. Changing the code so every copy looks different is cheap and automatic; changing what the code does is not, and behaviour is what current detection watches.

What single control helps most against this?

Restricting which interpreters ordinary accounts may run. Most chains need a scripting host at step two, very few people genuinely need one, and removing that permission breaks a large share of intrusions without needing to identify anything.

Is a reboot enough to clean an in-memory infection?

It clears the running code and does nothing about what was already taken or about persistence established elsewhere. Treating a reboot as remediation is how organisations end up reinfected within hours by the scheduled task nobody looked for.

How long does an infostealer take to do its work?

Minutes. It is not waiting for anything: it reads the credential stores, sends them, and often removes itself. Response designed around containing an active intruder does not fit an attack that finished before the alert was triaged.

Malware coverage

1,221 reports on malware, trojans and botnets, newest first.