MalwareBleeping Computer
9.5 — CRITICAL
GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
GhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender folder scans to never complete, leaving malware undetected. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A previously unknown attack vector, dubbed GhostTree, exploits Windows NTFS junctions and recursive file paths to evade folder scans and hide malware, potentially allowing attackers to remain undetected.
⚙️Technical Details
💥Impact Assessment
Severity: critical
Who Is at Risk
Users of Windows operating systems, particularly those with folder scanning capabilities such as EDR products
🛡️Recommended Actions
1Implement strict access controls for folders and directories
2Regularly update and patch affected Windows operating systems
3Monitor system logs for suspicious activity related to NTFS junctions and recursive file paths
📦Affected Products
Windows Operating Systems: All versions of Windows, including Windows Defender
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
