logo

Hackers Exploit Windows File Explorer and WebDAV to Distribute Malware

ID: 8ed82ba3-abf3-5a25-8cb3-7f82e9f84417

STIX ID: report--8ed82ba3-abf3-5a25-8cb3-7f82e9f84417

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-28

Date Updated: 2026-04-22

Author: Divya

...
...

Cofense Intelligence observed a campaign (since Feb 2024 with a surge in Sep 2024) where threat actors host malicious WebDAV servers on short-lived trycloudflare.com tunnels and use File Explorer shortcuts (file://, .url, .lnk) to trick victims into downloading multiple RAT families (XWorm, Async RAT, DcRAT). The technique bypasses browser protections and can evade some EDR solutions; the report provides Cloudflare Tunnel IOCs, notes targeting of European corporate networks (notably German-language invoice lures), and recommends disabling WebDAV client services and monitoring outbound SMB/WebDAV traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.