Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Non-malware is a ticking time bomb

by The Gurus
June 16, 2020
in This Week's Gurus
malware
Share on FacebookShare on Twitter

Non-malware is a massive and growing cybersecurity issue. Recent research from Carbon Black has shown that the issue is akin to a ticking time bomb with nearly two thirds (64%) of security researchers reporting that they’ve seen an increase in non-malware attacks since the beginning of 2016. The vast majority (93%) of security researchers surveyed also said non-malware attacks pose more of a business risk than commodity malware attacks.
A non-malware attack is one in which an attacker uses existing software, allowed applications and authorised protocols to carry out malicious activities. Non-malware attacks are capable of gaining control of computers without downloading any malicious files, hence the name.
Non-malware attacks are also referred to as fileless, memory-based or “living-off-the-land” attacks. Because non-malware attacks are fileless, they more easily bypass traditional AV protection and ML-based AV, which typically stop attacks based on files rather than behaviours.
This makes non-malware a particularly potent threat affecting organisations across all industries. There is no organisation or business that can escape the growing reach of the non-malware threat.
Attackers will use successful exploits to gain access to web browsers, Office-suite applications, native operating system tools (think PowerShell or Windows Management Instrumentation – WMI) and other applications that grant the attacker a level of execution freedom. These native tools grant users exceptional rights and privileges to carry out the most basic commands across a network that lead to valuable data.
Carbon Black’s research found that amongst the most common types of non-malware attacks that researchers reported seeing were: remote logins (55%), WMI-based attacks (41%), in-memory attacks (39%), PowerShell-based attacks (34%), and attacks leveraging Office macros (31%).
So what does the fightback against this threat look like?
What is clear is that it is early days for artificial intelligence (AI) and machine learning (ML) – at least for a while yet they are not the answer. Our research found that AI is considered by most security researchers to be in its nascent stages and not yet able to replace human decision making in cybersecurity.
Trust in both AI and ML will need to grow significantly before they become a viable solution to the non-malware problem and this may take a long time to accrue. The research showed that 87% of security researchers said it will be longer than three years before they trust AI to lead cybersecurity decisions.
In the meantime it is vital for organisations and the teams tasked with keeping data and networks safe that they find a solution that works and that they can trust, now.
This is where next-generation antivirus (NGAV) comes in! We know that legacy AV is ill-equipped to deal with non-malware threats. Indeed our research showed that security professionals already recognise this as being the case with two-thirds saying they were not confident legacy AV could protect an organisation from non-malware attacks.
Better detection and response to threats is imperative for security. NGAV is the solution to the non-malware problem and one that organisations need to – and increasingly are – looking to in order to provide the defence against these kinds of attacks. It is critical to their organisations that non-malware attacks are effectively stopped.
What makes non-malware a significant threat is a potent mix of rapid growth, the lack of protection of legacy AV, the lack of efficacy from AI and ML defence alternatives and the damage non-malware attacks can cause to an organisation.
Non-malware is the ticking time bomb organisations need to be aware of and take action now to prevent a potentially hugely damaging explosion either tomorrow, next week or the month after. If there is no effective defence it is only a matter of time before an attack gets through.
Bu Eric O’Neill, National Security Strategist, Carbon Black

Tags: CyberMalwaresecurityTechnology
ShareTweet
Previous Post

Hackers Attack Britain First Leaders' Website and Twitter Accounts: 'Stop Being Racist to Muslims'

Next Post

Why 61% of hacked webmasters don't receive a notification

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol