GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

Read full story on BleepingComputer
Share
GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
AI disclosure

Summary

GhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender folder scans to never complete, leaving malware undetected. [...]

Original reporting

Open original source

Related coverage

Read full article on BleepingComputer

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.