logo

GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

ID: b6ce3bb3-e897-5114-9993-b6f7acd20359

STIX ID: report--b6ce3bb3-e897-5114-9993-b6f7acd20359

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Sponsored by Varonis

...
...

GhostTree is a technique that abuses NTFS junctions/symbolic links to create recursive directory loops that generate an exponential number of valid file paths, causing recursive scans (dir/EDR products/Windows Defender) to hang and allowing malicious files in the parent directory to evade inspection; the issue was reported to Microsoft and subsequently patched, and defenders are advised to monitor anomalous junction creation and filesystem activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.