# GhostTree Attack Abuses Windows Junctions to Hide Malware From EDR and Security Tools


Researchers have discovered a novel file system evasion technique that exploits a fundamental feature of Windows NTFS to help attackers hide malicious files from endpoint detection and response (EDR) systems and antivirus tools. The attack, dubbed GhostTree, leverages NTFS junctions—a built-in file system feature designed for legitimate purposes—to create recursive directory loops that cause security scanners to either crash, timeout, or skip the malicious payload entirely.


The technique is particularly dangerous because it requires no elevated privileges and can be executed by any user with basic write permissions. Unlike advanced exploitation methods that target zero-day vulnerabilities, GhostTree works against the architecture of Windows file systems themselves, making it a fundamental challenge that security teams must address immediately.


## The Threat: A Deceptively Simple Evasion Method


GhostTree is not a new malware variant or a complex attack framework. Instead, it's a file system manipulation technique that turns a legitimate Windows feature into a weapon against defenders. By creating recursive junctions—directory pointers that loop back to parent directories—attackers can generate an effectively infinite number of valid file paths pointing to the same malicious executable.


Security tools tasked with recursively scanning directory structures can fall into these loops, becoming trapped in an endless traversal that never reaches the malicious files hidden within. Modern EDR solutions and antivirus software, which rely on deep directory scanning and enumeration, may:


  • Exhaust system resources trying to resolve infinite paths
  • Timeout during scans, leaving the folder unchecked
  • Skip the nested payload due to path length limitations
  • Fail to catalog the suspicious file for future analysis

  • What makes this technique particularly insidious is its simplicity and its exploitation of a fundamental design decision in Windows—one that has existed for decades and is unlikely to be patched away without breaking backward compatibility.


    ## Background and Context: NTFS Junctions Explained


    To understand GhostTree, it's essential to understand how Windows junctions work and why they exist.


    NTFS (New Technology File System) introduced several advanced features beyond simple file hierarchies. Two of the most powerful are:


    1. Junctions – NTFS reparse points that redirect one directory to another transparently

    2. Symbolic links – Similar to junctions but with broader capabilities


    These features were designed to solve legitimate problems:


  • Backward compatibility – Legacy applications expect files in specific locations; junctions let administrators reorganize storage without breaking old software
  • Storage optimization – Files can be referenced from multiple locations without duplication
  • Application migration – Redirect application folders during upgrades without reconfiguring software

  • Creating a junction requires only a single command and ordinary user permissions:


    mklink /J C:\LinkToFolder C:\TargetFolder

    No administrator privileges are needed. No audit trail is logged by default. Any user with write access to a directory can create a junction pointing anywhere on the system.


    ## Technical Details: From GhostBranch to GhostTree


    Researchers identified two related techniques, each more sophisticated than the last.


    ### GhostBranch: The Simple Loop


    The simpler variant, GhostBranch, creates a single recursive loop by pointing a child directory back to its parent:


    C:\Parent\program.exe        (original file)
    mklink /J C:\Parent\Child C:\Parent   (create junction)

    This creates a logical loop where C:\Parent\Child now contains everything the parent does, including itself. The result is an unlimited number of valid paths to the same file:


  • C:\Parent\program.exe
  • C:\Parent\Child\program.exe
  • C:\Parent\Child\Child\program.exe
  • C:\Parent\Child\Child\Child\program.exe

  • A security tool scanning recursively will keep following the loop infinitely, never reaching the end.


    ### GhostTree: The Branching Attack


    GhostTree escalates the concept by creating *multiple* junctions that all loop back to the parent:


    mklink /J C:\Parent\Child1 C:\Parent
    mklink /J C:\Parent\Child2 C:\Parent

    Now each level in the path has multiple branching options. A recursive scanner doesn't just follow one infinite loop—it faces exponential path combinations:


  • C:\Parent\Child1\program.exe
  • C:\Parent\Child2\program.exe
  • C:\Parent\Child1\Child1\program.exe
  • C:\Parent\Child1\Child2\program.exe
  • C:\Parent\Child2\Child1\program.exe

  • With just two junction points, a scanner attempting to enumerate all paths faces 2^n possible combinations at depth *n*. This causes:


  • Algorithmic explosion – Path enumeration becomes computationally prohibitive
  • Resource exhaustion – CPU and memory spike as the tool tries to catalog every path
  • Timeout triggers – Scans abort before completing, leaving malware undetected

  • There is one practical limit: Windows enforces a maximum path length of 260 characters by default (extendable to 32,767 via registry, but most tools don't support it). This limits how deep the recursive loops can go but still allows enough branching to defeat most scanners.


    ## How It Evades Detection: Why EDR Tools Struggle


    Modern endpoint detection and response platforms rely on several detection methods:


    | Detection Method | GhostTree Impact |

    |---|---|

    | File enumeration scans | Infinite loops cause timeouts |

    | Recursive directory crawling | Exponential path combinations overwhelm the tool |

    | Hash-based detection | File exists but is never reached during enumeration |

    | Behavioral monitoring | May still detect execution, but not the hidden staging |

    | Real-time file access monitoring | Works if triggered at execution time |


    The weakness is that many EDR tools perform *batch scans* during off-hours or deployment phases. These scheduled scans are vulnerable to timeout or resource exhaustion. Additionally, some tools may use cached directory listings that fail to update when new junctions are created.


    ## Implications for Organizations


    GhostTree exposes a fundamental gap in how security tools interact with the Windows file system:


    ### 1. Detection Blind Spot

    Malware staged in junction-based directory structures may evade initial detection, giving attackers a window to move laterally or establish persistence before EDR tools catch the execution.


    ### 2. Staged Attack Scenarios

    Attackers could use GhostTree to hide:

  • Credential harvesting tools
  • Lateral movement payloads
  • Ransomware staging directories
  • Second-stage malware waiting for command execution

  • ### 3. Privilege Escalation Staging

    Since any user can create junctions, an attacker with user-level access could stage privilege escalation exploits in hidden directory structures, then execute them when the timing is right.


    ### 4. Supply Chain Implications

    Third-party software deployed with write permissions to system directories could be trojanized by attackers using this technique, hiding malicious components from post-deployment scanning.


    ## Recommendations: Immediate and Long-Term Actions


    ### Immediate Actions (This Week)


    1. Update EDR Configuration

    - Test your EDR tool's handling of recursive junctions

    - Enable path depth limits if available

    - Configure timeouts to fail safely (alert on timeout, don't skip)

    - Check vendor patches or hotfixes


    2. Audit Existing Junctions

    Run a one-time audit to identify suspicious junctions:

    ```

    fsutil reparsepoint query C:\ /s

    ```

    Establish a baseline of legitimate junctions (many Windows systems have few or none).


    3. Restrict Junction Creation

    Use Group Policy to limit who can create junctions:

    - Policy: Computer Configuration > Windows Settings > Security Settings > File System

    - Target: Restrict to service accounts and administrators only

    - Audit: Enable auditing for junction creation attempts


    ### Medium-Term (This Month)


    4. Behavioral Detection

    - Monitor for mklink /J command execution

    - Alert on recursive directory structures with loops

    - Track file execution from unusual path depths

    - Correlate junction creation with subsequent file modifications


    5. Vendor Engagement

    - Contact your EDR vendor for GhostTree-specific detection

    - Request information on path traversal handling

    - Ask about recursive loop detection capabilities


    ### Long-Term Strategy (This Quarter)


    6. File System Hardening

    - Disable junctions entirely where not required (via registry)

    - Implement mandatory junction logging at the file system level

    - Use SACL (System Access Control Lists) to audit junction creation


    7. Process-Level Monitoring

    - Monitor what processes access which files

    - Use guaranteed file access logging to catch execution even if directory scans fail

    - Implement guaranteed file auditing on sensitive directories


    8. Threat Hunting

    - Hunt for junctions in unusual locations (temp directories, user profiles, staging areas)

    - Look for patterns of rapid junction creation followed by file execution

    - Correlate with suspicious process execution


    ---


    ## HackWire Analysis


    Why GhostTree matters now: This attack highlights a critical blind spot in how modern security tools interact with Windows file systems. While EDR solutions have become sophisticated at detecting malware behaviors, process execution, and network communications, they remain vulnerable to simple file system tricks that exploit design constraints rather than software bugs. The fact that this technique requires no privileges and no exploits makes it immediately accessible to any attacker with basic system access—and difficult to defend against without architectural changes to how scanners work.


    Pattern recognition: GhostTree is part of a broader trend of *fileless* and *filesystem-based* evasion techniques. We've seen attackers abuse alternate data streams, hard links, and now junctions. Each technique exploits a legitimate Windows feature that defenders overlook because they're designed for compatibility, not security. The common thread: Windows maintains backward compatibility with legacy features, and attackers exploit that tension.


    Hidden risk: The biggest danger is timing. An attacker could stage a multi-stage payload using GhostTree, hide it from EDR for weeks, and only execute it when a specific condition is met—a particular user logs in, an application launches, a scheduled task runs. By then, the staging files have aged past typical retention periods, and the attack appears to "just happen" with no obvious preparation.


    Concrete next steps: Organizations should prioritize three things: (1) run fsutil to baseline existing junctions—if you find any you don't recognize, treat them as indicators of compromise; (2) test your EDR against synthetic GhostTree structures before attackers do it for real; and (3) contact your security vendor today about guidance, not next quarter. The longer you wait, the higher the probability someone in your network is already testing this.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) and [Endpoint Security](https://www.hackwire.news/category/endpoint-security) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Evasion Techniques](https://www.hackwire.news/category/evasion-techniques)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)