Fileless Storage

T1027.011

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may store data in "fileless" formats to conceal malicious activity from defenses. Fileless storage can be broadly defined as any format other than a file. Common examples of non-volatile fileless storage in Windows systems include the Windows Registry, event logs, or WMI repository. Shared memory directories on Linux systems (`/dev/shm`, `/run/shm`, `/var/run`, and `/var/lock`) and volatile directories on Network Devices (`/tmp` and `/volatile`) may also be considered fileless storage, as files written to these directories are mapped directly to RAM and not stored on the disk..

Similar to fileless in-memory behaviors such as Reflective Code Loading and Process Injection, fileless data storage may remain undetected by antivirus and other endpoint security tools that can only access specific file formats from disk storage. Leveraging fileless storage may also allow adversaries to bypass the protections offered by read-only file systems in Linux.

Adversaries may use fileless storage to conceal various types of stored data, including payloads/shellcode (potentially being used as part of Persistence) and collected data not yet exfiltrated from the victim (e.g., Local Data Staging). Adversaries also often encrypt, encode, splice, or otherwise obfuscate this fileless data when stored.

Some forms of fileless storage activity may indirectly create artifacts in the file system, but in central and otherwise difficult to inspect formats such as the WMI (e.g., `%SystemRoot%\System32\Wbem\Repository`) or Registry (e.g., `%SystemRoot%\System32\Config`) physical files.

Detection rules4

Rules on DetectionCode tagged with T1027.011.

Sigma1

RuleLevelLog source
Process Execution From Shared Memory Directoryhighlinux / process_creation

Splunk3

RuleTypeRiskData source
PowerShell WebRequest Using Memory StreamTTPNULLPowershell Script Block Logging 4104
Windows Njrat Fileless Storage via RegistryTTPNULLSysmon EventID 13
Windows Registry Payload InjectionTTPNULLSysmon EventID 13

Groups2

Software27

Show 3 more

Campaigns2

Procedure examples31

Groups2

Used byProcedure example
GroupAPT32

APT32's backdoor has stored its configuration in a registry key.

GroupTurla

Turla has used the Registry to store encrypted and encoded payloads.

Software27

Used byProcedure example
MalwareChaes

Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry.

MalwareCHOPSTICK

CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry.

MalwareComRAT

ComRAT has stored encrypted orchestrator code and payloads in the Registry.

MalwareDarkWatchman

DarkWatchman can store configuration strings, keylogger, and output of components in the Registry.

MalwareExaramel for Windows

Exaramel for Windows stores the backdoor's configuration in the Registry in XML format.

MalwareGelsemium

Gelsemium can store its components in the Registry.

MalwareGrandoreiro

Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.

MalwareMosquito

Mosquito stores configuration values under the Registry key HKCU\Software\Microsoft\[dllname].

View all 27 software examples

Campaigns2

Used byProcedure example
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors stroed payloads in Windows CLFS (Common Log File System) transactional logs.

CampaignQuad7 Activity

Quad7 Activity has infected victim network devices by storing artifacts in the /tmp directory which is volatile in memory and will clear its contents upon shutdown or restart.

References8

  1. Akami Frog4Shell 2024 Open source
    Ori David. (2024, February 1). Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal. Retrieved September 24, 2024.
  2. Aquasec Muhstik Malware 2024 Open source
    Nitzan Yaakov. (2024, June 4). Muhstik Malware Targets Message Queuing Services Applications. Retrieved September 24, 2024.
  3. Bitsight 7777 Botnet Open source
    Batista, João. Gi7w0rm. (2024, August 27). Retrieved June 5, 2025.
  4. CISCO Nexus 900 Config Open source
    CISCO. (2021, September 14). Cisco Nexus 9000 Series NX-OS Fundamentals Configuration Guide, Release 7.x. Retrieved June 5, 2025.
  5. Elastic Binary Executed from Shared Memory Directory Open source
    Elastic. (n.d.). Binary Executed from Shared Memory Directory. Retrieved September 24, 2024.
  6. Microsoft Fileless Open source
    Microsoft. (2023, February 6). Fileless threats. Retrieved March 23, 2023.
  7. SecureList Fileless Open source
    Legezo, D. (2022, May 4). A new secret stash for “fileless” malware. Retrieved March 23, 2023.
  8. Sysdig Fileless Malware 23022 Open source
    Nicholas Lang. (2022, May 3). Fileless malware mitigation. Retrieved September 24, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.