news.mlab.sh
Back to the feed
threat-intel

GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

High
Summary

Security researchers have discovered a novel technique, dubbed "GhostTree," used by attackers to evade detection by security tools. This method leverages recursive loops created using NTFS junctions to hide malicious files within Windows file systems. Attackers create junctions that point back to their parent directories, generating effectively infinite file paths, making it difficult for traditional file scanning methods, including EDR products, to identify the hidden malware. This technique highlights the potential for misconfigured or overlooked file system features to be exploited for malicious purposes.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.