GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
ID: b6ce3bb3-e897-5114-9993-b6f7acd20359
STIX ID: report--b6ce3bb3-e897-5114-9993-b6f7acd20359
Feed Name: Bleeping Computer
Threat Score
GhostTree is a technique that abuses NTFS junctions/symbolic links to create recursive directory loops that generate an exponential number of valid file paths, causing recursive scans (dir/EDR products/Windows Defender) to hang and allowing malicious files in the parent directory to evade inspection; the issue was reported to Microsoft and subsequently patched, and defenders are advised to monitor anomalous junction creation and filesystem activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
