Fileless PowerShell Execution Caught in Memory
ClickFix social engineering became the dominant malware delivery method between March and May 2026, according to ReliaQuest: fake browser error pages trick users into copying and running malicious scripts. Many of these scripts are fileless — PowerShell payloads that execute entirely in memory with no file dropped to disk, bypassing traditional file scanning. This demo runs a benign PowerShell command that only opens Calculator, delivered through a .docm container, to reproduce that execution pattern safely. Adaptive Sandbox detonates the sample in a controlled virtual machine and observes the in-memory behavior: script interpretation, process tree, and network calls. Even with no malicious file on disk, the sandbox's behavioral analysis exposes the full attack chain for detection and response.
Attack Technique
Fileless PowerShell execution
MITRE ATT&CK
T1059.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗