Malware infects computers on a corporate network after users visit a number of well-known Russian online resources. Malware is loaded via the teasers on Russian news sites AdFox.ru and JAVAW.EU domains. The infection mechanism used by this malware proved to be very difficult to identify. The only thing they had in common was that they both used AdFox advertisement management system codes, through which teaser exchange was arranged. The malware is a very rare kind of malware the so-called bodiless malicious programs that operate only in the infected computers RAM.”]
Source: https://securelist.com/a-unique-bodiless-bot-attacks-news-site-visitors/32383/