Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Windows File Explorer for Malware Delivery

Hackers Exploit Windows File Explorer for Malware Delivery

Posted on February 28, 2026 By CWS

Cybercriminals are exploiting a legacy feature of Windows File Explorer to deliver malware, successfully evading traditional web browser defenses and endpoint detection systems. This strategy leverages Web-based Distributed Authoring and Versioning (WebDAV) to deceive users into running harmful software, as reported by Kahng An from the Cofense Intelligence Team.

The Vulnerability in WebDAV

WebDAV, an older protocol for remote file management, is being manipulated by attackers despite Microsoft’s decision to formally deprecate its support in Windows File Explorer as of November 2023. Nonetheless, the functionality is still accessible on many systems. Cybercriminals exploit this by directing victims to malicious links that cause File Explorer to connect directly to rogue WebDAV servers.

This technique bypasses web browsers entirely, meaning that users do not encounter standard browser security alerts or download prompts. The remote server masquerades as a local folder, which can mislead users into believing that downloaded files are safe and stored locally. Although Windows issues a default warning when executing files from a remote network, this alert is often disregarded by users accustomed to legitimate file shares.

Methods of Exploitation

Three main methods are used by attackers to execute this exploit, frequently involving the DavWWWRoot keyword to target a remote server’s root directory. First, direct linking uses the file:// URI scheme to open remote folders directly within the system’s file browser. Secondly, URL shortcut files (.url) employ Windows UNC paths to invisibly connect to remote servers over HTTP or HTTPS. Lastly, LNK shortcut files (.lnk) typically contain concealed commands that activate Command Prompt or PowerShell to download and run malicious scripts without user knowledge.

A unique technical characteristic of this tactic is the automatic DNS lookup triggered when a directory containing a malicious .url file with a UNC path is opened. This sends a TCP SYN packet to the attacker’s infrastructure, indicating payload activation even if the file is not actively clicked by the user.

Impact and Future Outlook

Since late 2024, there has been a surge in campaigns utilizing this method, primarily aimed at deploying Remote Access Trojans (RATs) to illicitly control systems. Cofense reports that 87% of Active Threat Reports linked to this tactic involve multiple RATs, with XWorm RAT, Async RAT, and DcRAT being the most prevalent.

These attacks predominantly target European corporate networks, with roughly 50% of phishing emails composed in German, often disguised as financial documents, while 30% are in English. To evade detection, threat actors set up transient WebDAV servers using free Cloudflare Tunnel demo accounts hosted on trycloudflare[.]com. This tactic complicates detection efforts by routing malicious traffic through legitimate Cloudflare infrastructure before the temporary servers are taken offline.

Security teams are advised to monitor for unusual network activity originating from Windows Explorer and educate users to check the address bar in File Explorer for unfamiliar IP addresses. The broader risk is that similar abuses could potentially extend to other enterprise protocols like FTP and SMB.

Cyber Security News Tags:Cloudflare, cyber threat, Cybersecurity, endpoint security, malware delivery, network security, Phishing, Remote Access Trojans, WebDAV, Windows File Explorer

Post navigation

Previous Post: Canadian Tire Data Breach Exposes Millions of Accounts
Next Post: OpenClaw Security Flaw Allows AI Agent Hijacking

Related Posts

New EDR-Freeze Tool That Puts EDRs And Antivirus Into A Coma State New EDR-Freeze Tool That Puts EDRs And Antivirus Into A Coma State Cyber Security News
NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks NVIDIA DGX Spark Vulnerabilities Let Attackers Execute Malicious Code and DoS Attacks Cyber Security News
GhostLock Exploits File-Sharing to Mimic Ransomware GhostLock Exploits File-Sharing to Mimic Ransomware Cyber Security News
New Malware Attack Weaponizing LNK Files to Install The REMCOS Backdoor on Windows Machines New Malware Attack Weaponizing LNK Files to Install The REMCOS Backdoor on Windows Machines Cyber Security News
Android AI Malware Uses Google’s Gemini for New Threats Android AI Malware Uses Google’s Gemini for New Threats Cyber Security News
A Buyer’s Guide for CISOs A Buyer’s Guide for CISOs Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Exploitation of PAN-OS Security Flaw Intensifies
  • Post-Quantum Cryptography Gains Momentum
  • Critical Exploitation of PAN-OS Vulnerability CVE-2026-0257
  • Google Chrome Enhances Security with Device-Bound Credentials
  • GREYVIBE Hackers Exploit AI for Sophisticated Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Exploitation of PAN-OS Security Flaw Intensifies
  • Post-Quantum Cryptography Gains Momentum
  • Critical Exploitation of PAN-OS Vulnerability CVE-2026-0257
  • Google Chrome Enhances Security with Device-Bound Credentials
  • GREYVIBE Hackers Exploit AI for Sophisticated Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark