GhostTree Attack Exploits NTFS Junctions to Evade Security Scans

GhostTree Attack Exploits NTFS Junctions to Evade Security Scans

First seen 16 Jun 2026, 23:11 UTC BleepingcomputerScworldinfo.varonis.com 92% similarity 67.5

Article Content

Browse articles
ThreatCluster

The GhostTree technique allows attackers to create recursive loops using NTFS junctions, enabling them to hide malware from security tools. This method requires only write access to a folder, making it accessible to any user without special privileges. By pointing a junction back to its parent directory, attackers can generate an almost infinite number of valid file paths, causing directory scanning tools to hang indefinitely. As a result, malicious files placed in the parent directory remain undetected. Microsoft initially closed a report on this issue but later released a patch. Security professionals are advised to monitor file system activity for anomalous junction creation as a potential indicator of malicious intent. The technique poses significant risks to organizations relying on traditional endpoint detection and response (EDR) solutions.

Key Points: • GhostTree exploits NTFS junctions to create recursive loops, evading security scans. • No special privileges are needed to create junctions, allowing widespread potential abuse. • Microsoft has released a patch following reports of the technique's exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-06-16
GhostTree technique reported
The GhostTree technique was disclosed, revealing how attackers can hide malware using NTFS junctions.
Bleepingcomputer
2026-06-16
Security implications highlighted
Varonis emphasized the need for monitoring file system activity to detect anomalous junction creation as a sign of potential attacks.
Scworld

Community

Browse all →

Tracked Entities in This Story