Hackers Exploit Windows File Explorer and WebDAV to Distribute Malware
ID: 8ed82ba3-abf3-5a25-8cb3-7f82e9f84417
STIX ID: report--8ed82ba3-abf3-5a25-8cb3-7f82e9f84417
Feed Name: GBHackers
Cofense Intelligence observed a campaign (since Feb 2024 with a surge in Sep 2024) where threat actors host malicious WebDAV servers on short-lived trycloudflare.com tunnels and use File Explorer shortcuts (file://, .url, .lnk) to trick victims into downloading multiple RAT families (XWorm, Async RAT, DcRAT). The technique bypasses browser protections and can evade some EDR solutions; the report provides Cloudflare Tunnel IOCs, notes targeting of European corporate networks (notably German-language invoice lures), and recommends disabling WebDAV client services and monitoring outbound SMB/WebDAV traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
