Social engineering and phishing attacks
Back to Blog
Threat Intel

Advanced Social Engineering & Malware-Free Attacks

PublishedJune 8, 2026
Read time9 min read
Share
Originally reported viaIBM X-Force Threat Intelligence Index 2026 · FBI Internet Crime Report 2025 · Verizon DBIR 2026

Malware-free attacks now represent 71% of all incidents tracked by IBM X-Force in 2026, up from 58% in 2024. Attackers are using valid credentials, legitimate system tools, and trusted cloud services to achieve their objectives — leaving no malicious binary for endpoint protection to detect. The FBI's Internet Crime Complaint Centre attributed $4.6 billion in losses to BEC and phishing-related fraud in 2025, a 33% year-on-year increase.

AI-amplified phishing and vishing

Modern phishing kits use AI to personalise lure content at the individual recipient level — referencing real colleagues, recent company events, and plausible internal processes — increasing click rates by an estimated 3–5× compared to generic templates. Vishing operations combine AI-cloned executive voices with urgency-framed pretexts to bypass wire authorisation controls. In the most sophisticated BEC cases, real-time video deepfakes replace voice calls entirely during finance team interactions.

Source: IBM X-Force Threat Intelligence Index 2026
IBM X-Force found that AI-generated phishing emails are now largely indistinguishable from legitimate internal communications in blind testing of enterprise employees, with a 94% pass rate in simulations using personalised AI lures compared to 63% for generic templates.

Living-off-the-land: hiding in plain sight

Living-off-the-land (LOTL) techniques abuse legitimate operating system tools and cloud services — PowerShell, WMI, RDP, certutil, msiexec, and legitimate file-sharing platforms — to execute attacker objectives without introducing malicious code. Because these tools are used routinely in normal operations, signature-based and even many ML-based endpoint controls cannot reliably distinguish malicious from legitimate usage without robust behavioural baselining.

Source: Verizon DBIR 2026
The DBIR 2026 found LOTL techniques present in 61% of post-intrusion activity, and that the median dwell time for credential-based intrusions without malware deployment was 11 days — nearly three times longer than malware-based intrusions, largely because traditional detection triggers were absent.

Why the detection model must shift

The core problem is that LOTL and credential-abuse attacks succeed specifically because they look normal at the individual event level. Detection requires context — a sequence of actions, user risk scores, anomalous access patterns, and deviation from established behavioural baselines. UEBA (User and Entity Behaviour Analytics), process lineage tracking, and identity-aware SIEM correlation are the primary defences.

Security operations centre analyst reviewing behavioural analytics
Behavioural analytics — not signatures — is the primary detection control for malware-free attacks.
  • Deploy a UEBA layer in your SIEM to baseline normal user and entity behaviour. Alert on statistically anomalous deviations, not just rule matches.
  • Build LOTL detection rules targeting LOLBin abuse patterns: unusual PowerShell encoded command usage, certutil download cradles, msiexec executing from user-writable paths.
  • Implement user risk scoring combining phishing simulation performance, login anomalies, and unusual data access.
  • Enforce DMARC, DKIM, and SPF on all domains. Monitor for lookalike domains targeting your brand.
  • Establish a mandatory out-of-band verification protocol for wire transfers, payroll changes, and credential resets — verification via the same email thread is not verification.
  • Run quarterly tabletop exercises simulating a credential-only intrusion with no malware. Most IR plans are optimised for malware incidents.

When attackers stop bringing malware, your detection stack that was built around malware stops working. Behavioural baselines and identity context are the only signals that remain.

Dev Krishnamurthy, Threat Intel Researcher · Furix Feed

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.