FeedMalwareGhostTree Attack Abused Recursive Windows Junctions to Hide ...
MalwareBleeping Computer
9.5CRITICAL

GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

📅 16 June 2026 at 14:17 UTC📰 Bleeping ComputerView original source ↗
GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

GhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender folder scans to never complete, leaving malware undetected. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A previously unknown attack vector, dubbed GhostTree, exploits Windows NTFS junctions and recursive file paths to evade folder scans and hide malware, potentially allowing attackers to remain undetected.

⚙️Technical Details
💥Impact Assessment
Severity: critical
Who Is at Risk
Users of Windows operating systems, particularly those with folder scanning capabilities such as EDR products
🛡️Recommended Actions
1Implement strict access controls for folders and directories
2Regularly update and patch affected Windows operating systems
3Monitor system logs for suspicious activity related to NTFS junctions and recursive file paths
📦Affected Products
Windows Operating Systems: All versions of Windows, including Windows Defender

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed