Executive Summary
In May 2026, Varonis Threat Labs identified a novel evasion technique named 'GhostTree' that exploits NTFS junctions in Windows systems. By creating recursive directory loops, attackers can generate an effectively infinite number of file paths, causing Endpoint Detection and Response (EDR) tools to hang during recursive scans. This manipulation allows malicious files to remain undetected, as the scanning process becomes trapped in the loop and fails to complete. The technique requires only standard user permissions, making it accessible without administrative rights. (varonis.com)
The discovery of GhostTree underscores the evolving sophistication of malware evasion tactics. As attackers increasingly exploit legitimate system features to bypass security measures, organizations must enhance their detection capabilities and adopt comprehensive monitoring strategies to identify and mitigate such advanced threats.
Why This Matters Now
The GhostTree technique highlights a critical vulnerability in current EDR systems, emphasizing the need for organizations to reassess and strengthen their security protocols to detect and prevent such sophisticated evasion methods.
Attack Path Analysis
An attacker exploited NTFS junctions to create recursive directory loops, causing endpoint detection and response (EDR) tools to hang and fail to scan malicious files. This allowed the attacker to maintain persistence and evade detection, potentially leading to data exfiltration or further system compromise.
Kill Chain Progression
Initial Compromise
Description
The attacker gained access to the system, possibly through phishing or exploiting a vulnerability, and created NTFS junctions to establish recursive directory loops.
MITRE ATT&CK® Techniques
NTFS File Attributes
Hidden File System
Hidden Files and Directories
Indicator Removal on Host: File Deletion
File and Directory Discovery
Indirect Command Execution
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Malware Protection Mechanisms
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
GhostTree evasion technique threatens endpoint security in highly regulated environments, potentially bypassing malware detection systems protecting sensitive financial data and transactions.
Health Care / Life Sciences
Windows junction-based malware hiding technique poses significant risk to medical systems and patient data, potentially evading EDR solutions in HIPAA-compliant environments.
Government Administration
Recursive directory structure attack could compromise government endpoint security, enabling threat actors to hide malware from scanning tools in critical infrastructure systems.
Computer Software/Engineering
GhostTree technique directly impacts software development environments using Windows systems, potentially allowing malware persistence while evading traditional endpoint detection and response solutions.
Sources
- GhostTree Attack Abused Recursive Windows Junctions to Hide Malwarehttps://www.bleepingcomputer.com/news/security/ghosttree-attack-abused-recursive-windows-junctions-to-hide-malware/Verified
- GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Securityhttps://www.varonis.com/blog/ghosttree-ntfs-trickVerified
- GhostTree Technique Can Disrupt EDR Scanning and Hide Malicious Fileshttps://diamatix.com/ghosttree-edr-ntfs-recursive-loops/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been limited to the compromised workload, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been constrained, limiting their access to sensitive resources.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network may have been restricted, reducing the risk of widespread compromise.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control communications could have been detected and disrupted, limiting their ability to manage the compromised system.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been constrained, reducing the risk of sensitive information being leaked.
The potential impact of the attack may have been limited to the initially compromised workload, reducing overall operational disruption.
Impact at a Glance
Affected Business Functions
- Endpoint Detection and Response (EDR) Systems
- Antivirus Scanning Processes
- File Integrity Monitoring
Estimated downtime: N/A
Estimated loss: N/A
Potential for undetected malware to reside on systems, leading to unauthorized access or data exfiltration.
Recommended Actions
Key Takeaways & Next Steps
- • Implement endpoint detection and response (EDR) solutions that can detect and handle recursive directory structures to prevent evasion techniques like GhostTree.
- • Regularly audit and monitor file system activities to identify and respond to anomalous behaviors, such as the creation of recursive NTFS junctions.
- • Apply the principle of least privilege to limit the ability of users and processes to create or modify junctions and symbolic links.
- • Educate security teams about advanced evasion techniques and ensure they are equipped to recognize and mitigate such threats.
- • Keep systems and security tools updated to incorporate patches and improvements that address known vulnerabilities and evasion methods.



