logo

The Explorer Trap: How Hackers Turn Windows File Explorer into a Silent Portal for Remote Access Trojans

ID: 26a4a3b7-c8a0-5c81-981c-05ef732984e4

STIX ID: report--26a4a3b7-c8a0-5c81-981c-05ef732984e4

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-27

Date Updated: 2026-04-23

Author: Ddos

...
...

Cofense Intelligence uncovered a growing campaign that leverages WebDAV support in Windows File Explorer and malicious .url/.lnk shortcuts to silently download Remote Access Trojans (notably XWorm, Async RAT, and DcRAT). Attackers host WebDAV servers on legitimate Cloudflare Tunnel demo domains to evade detection, exploit UNC shortcut behavior that can beacon to infrastructure without user clicks, and primarily target European corporate users using invoice-themed lures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.