$ intel.mask2.ca

ADVISORY · 2026-06-16 · SRC BLEEPINGCOMPUTER · HIGH
2026-06-16 high REL 7/10

GhostTree Attack Exploits Windows Junctions to Evade Microsoft Defender Scans

post-secondarygovernmenthealthcareenergyfinancegeneral

A technique called GhostTree leverages recursive NTFS junctions to create numerous valid Windows file paths that can cause Microsoft Defender folder scans to hang indefinitely. This allows malware to remain hidden on systems while antivirus protection appears to be functioning normally. The method targets a fundamental weakness in how Windows file system scanning handles symbolic link structures.

Why it matters in Western Canada: Organizations across Western Canada relying on Microsoft Defender for endpoint protection—including universities, government agencies, and healthcare providers—could face undetected malware infections if systems use vulnerable scan configurations.


Summary generated from the original advisory. Read the full source: bleepingcomputer

Source
https://www.bleepingcomputer.com/news/security/ghosttree-attack-abused-recursive-windows-junctions-to-hide-malware/
CVEs
None listed
Tags
windows defender, malware evasion, ntfs junctions, endpoint protection, ghosttree
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)