GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
Security researchers have discovered a novel technique, dubbed "GhostTree," used by attackers to evade detection by security tools. This method leverages recursive loops created using NTFS junctions to hide malicious files within Windows file systems. Attackers create junctions that point back to their parent directories, generating effectively infinite file paths, making it difficult for traditional file scanning methods, including EDR products, to identify the hidden malware. This technique highlights the potential for misconfigured or overlooked file system features to be exploited for malicious purposes.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data