logo

Hackers Abuse Windows File Explorer and WebDAV for Stealthy Malware Delivery

ID: 15d9c6fe-42e1-5d36-a93a-6bcfb9e395f3

STIX ID: report--15d9c6fe-42e1-5d36-a93a-6bcfb9e395f3

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-28

Date Updated: 2026-04-21

Author: Dhivya

...
...

Cybercriminals are abusing legacy WebDAV support in Windows File Explorer to bypass browser protections and distribute RATs by forcing Explorer to mount remote WebDAV servers (via file:// links, .url UNC DavWWWRoot paths, and malicious .lnk files). Campaigns observed since late 2024 deliver multiple RAT families (XWorm, AsyncRAT, DcRAT), target European corporate networks (many German-language phishing lures), and hide infrastructure using short-lived Cloudflare Tunnel demo domains (trycloudflare.com); several malicious trycloudflare domains are listed as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.