Fileless malware can be a difficult threat analyze and detect. It shouldn’t be a surprise that an increasing number of new malware threats are fileless, as threat actors use this technique to make both detection and forensic investigation more difficult. We recently found a new cryptocurrency miner (which we detect as TROJ64_COINMINER.QO) that uses this particular technique as well.
Post from: Trendlabs Security Intelligence Blog - by Trend Micro
Cryptocurrency Miner Uses WMI and EternalBlue To Spread Filelessly