Skip to main content
← Back to Demos
Script Injection advanced · 15 min

Fileless PowerShell Execution Caught in Memory

ClickFix social engineering became the dominant malware delivery method between March and May 2026, according to ReliaQuest: fake browser error pages trick users into copying and running malicious scripts. Many of these scripts are fileless — PowerShell payloads that execute entirely in memory with no file dropped to disk, bypassing traditional file scanning. This demo runs a benign PowerShell command that only opens Calculator, delivered through a .docm container, to reproduce that execution pattern safely. Adaptive Sandbox detonates the sample in a controlled virtual machine and observes the in-memory behavior: script interpretation, process tree, and network calls. Even with no malicious file on disk, the sandbox's behavioral analysis exposes the full attack chain for detection and response.

Attack Technique

Fileless PowerShell execution

MITRE ATT&CK

T1059.001 ↗

Platforms

linuxmacoswindows

File Types

.sh

MetaDefender Capabilities

Adaptive Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---