logo

Abusing Windows File Explorer and WebDAV for Malware Delivery

ID: 5d60a0c1-699b-528b-a566-56fab87949fc

STIX ID: report--5d60a0c1-699b-528b-a566-56fab87949fc

Feed Name: Cofense Blog

Threat Score
72/100

Date Published: 2026-02-25

Date Updated: 2026-04-27

Author: Cofense

...
...

This Cofense Intelligence report describes active phishing campaigns that exploit Windows File Explorer's WebDAV capabilities and Cloudflare Tunnel demo instances to host and deliver remote access trojans (notably XWorm, Async RAT, and DcRAT) via .url and .lnk shortcuts, UNC paths, and script chains; it provides example Cloudflare Tunnel domains, highlights that 87% of ATRs using this tactic deliver RATs, notes campaign language targeting (mainly German and English finance-themed lures), and offers detection and mitigation guidance including EDR hunting for shortcut files and monitoring trycloudflare.com demo instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.