Threat reportThreat IntelligenceTL-2026-0821

GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide Malware

mediumPATCHED

GhostTree / GhostBranch (TL-2026-0821), also tracked as GhostTree, is a medium-severity tracked intrusion set, first published 2026-06-16. It has no confirmed attribution, affects Microsoft Microsoft Defender Antivirus (Windows Defender) recursive, maps to 14 MITRE ATT&CK techniques (T1027, T1036, T1036.005), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-0821

Threat ID
TL-2026-0821
Also known as
GhostTree, GhostBranch
Severity
MEDIUM
Status
PATCHED
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
18

How GhostTree / GhostBranch works

GhostTree (and its single-junction variant GhostBranch) abuses legitimate Windows NTFS directory junctions to manufacture an astronomically large number of valid file paths that all resolve to the same location, causing recursive directory scanners — including Windows Defender and EDR products — to loop, hang, or skip files and leave co-located malware unscanned. The technique requires only standard-user write permissions (mklink /J). Microsoft initially closed the report as 'not crossing a security boundary' before patching the underlying recursive-scan behavior.

GhostTree is a Windows defense-evasion technique disclosed by Varonis Threat Labs (researcher Dolev Taler) on 2026-06-16. It weaponizes NTFS directory junctions — reparse points (IO_REPARSE_TAG_MOUNT_POINT) that transparently redirect directory access — to create self-referential, recursive directory loops on disk.

The simpler variant, GhostBranch, uses a single junction that points a child directory back at its own parent: `mklink /J C:\Parent\Child C:\Parent`. Because the junction resolves to its ancestor, the file system exposes an endless ladder of valid paths to the same file: C:\Parent\Child\Program.exe, C:\Parent\Child\Child\Program.exe, and so on. Any tool that walks the directory tree recursively will keep descending into the loop and never terminate.

GhostTree amplifies this by creating multiple child junctions at each level that each point back to the parent (e.g. `mklink /J C:\Parent\Child1 C:\Parent` and `mklink /J C:\Parent\Child2 C:\Parent`), producing a branching tree. Varonis calculates that with binary branching constrained by Windows' path-length limits the structure yields roughly 2^126 ≈ 8.5 × 10^37 distinct valid paths to a single executable — vastly more than the estimated number of grains of sand on Earth (~8.5 × 10^18).

Windows enforces a traditional maximum path length (MAX_PATH) of 260 characters, which caps recursion at approximately 126 nested directory levels when single-character folder names are used. This limit can be raised to 32,767 characters via the LongPathsEnabled registry value, though many applications and utilities still cannot handle paths beyond 260, so attackers can use the legacy limit while still defeating scanners.

The security impact is on recursive directory traversal. Varonis tested the technique against Windows Defender (Microsoft Defender Antivirus) and confirmed it could evade folder scans: the scanning engine becomes consumed following the directory loop and ultimately hangs without completing, so malware placed alongside the junctions remains unscanned and undetected by the endpoint agent. The same failure mode affects EDR products that perform unbounded recursive directory scans. This behaves as a denial-of-service against the security scanner itself, providing cover for arbitrary co-located payloads.

The technique is notable because it requires only standard write permissions rather than administrative privileges — any low-privileged user (or a foothold process) can create junctions with the built-in mklink utility or the CreateSymbolicLink / DeviceIoControl(FSCTL_SET_REPARSE_POINT) APIs. Varonis reported the issue to Microsoft, who initially closed the ticket with the explanation that 'bypassing Defender is not crossing a security boundary,' but Microsoft subsequently patched the recursive-scanning behavior regardless.

No CVE was assigned. No in-the-wild exploitation, malware family, threat-actor attribution, or network indicators (C2 IPs, domains, or file hashes) were reported in the source material; consequently there is no network infrastructure to correlate (BeaconBeagle pivot is not applicable). The indicators below are behavioral/host-based artifacts of the technique itself. Defenders are advised to monitor file-system activity at the data layer — anomalous junction/reparse-point creation and recursive directory structures that should not exist under normal operation — rather than relying solely on recursive native scanning, and to apply current Microsoft Defender platform updates.

MITRE ATT&CK techniques used in TL-2026-0821

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1070 Indicator Removal; T1070.004 File Deletion; T1564 Hide Artifacts; T1564.004 NTFS File Attributes

Execution

T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1106 Native API

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Impact

T1499 Endpoint Denial of Service

Affected products and versions in GhostTree / GhostBranch

  • Microsoft — Microsoft Defender Antivirus (Windows Defender) recursive directory scanning
    Vulnerable versions: Recursive-scan engine prior to fix (specific build undisclosed)
    Fixed in: Patched Defender platform/engine update (date undisclosed)
  • Microsoft — Windows NTFS directory junctions / reparse points
    Vulnerable versions: Junction creation available to standard users on supported Windows versions
  • Multiple — EDR / antivirus products performing unbounded recursive directory traversal
    Vulnerable versions: Implementations without reparse-loop / depth handling

Remediation for GhostTree / GhostBranch

Patches

  • Microsoft patched the underlying recursive directory-scanning behavior in Microsoft Defender Antivirus (specific KB/build and date not disclosed in public reporting).

Immediate actions

  • Apply current Microsoft Defender Antivirus platform/engine updates, which include the fix for the recursive directory-scanning behavior abused by GhostTree/GhostBranch.
  • Hunt for self-referential NTFS directory junctions whose reparse target resolves to an ancestor of the link itself (recursive loops).

Workarounds

  • Detect and remove malicious junctions with fsutil reparsepoint query / fsutil reparsepoint delete or PowerShell reparse-point inspection.
  • Restrict or alert on junction creation in sensitive directories; treat single-character nested directory chains as suspicious.

Longer-term hardening

  • Monitor file-system activity at the data layer (e.g. minifilter/audit telemetry) to detect anomalous junction/reparse-point creation and recursive directory structures, rather than relying solely on recursive native file scanners.
  • Adopt defense-in-depth so that a single recursive-scan evasion does not leave endpoints blind; correlate process creation (mklink/cmd.exe) with reparse-point creation events.
  • Configure scanners/EDR with traversal depth limits, loop/cycle detection, and reparse-point handling so directory walks terminate safely.

Weaknesses (CWE) in GhostTree / GhostBranch

CWE-674, CWE-59

Timeline of GhostTree / GhostBranch

  • Varonis recommended data-layer file-system monitoring for anomalous junction/reparse-point creation and recursive directory structures rather than relying solely on recursive native scanning.
  • No CVE was assigned and no in-the-wild exploitation, malware family, or threat-actor attribution was reported; the disclosure is a defensive PoC against recursive directory scanners.
  • Researchers noted the recursion depth can be extended beyond the 260-character MAX_PATH limit to 32,767 characters by enabling the LongPathsEnabled registry value.
  • Varonis documented two variants: GhostBranch (single self-referential junction yielding ~126 nested path levels) and GhostTree (multi-junction branching yielding ~2^126 ≈ 8.5 × 10^37 distinct paths to one file).
  • Technique covered by BleepingComputer, Cyber Security News, GBHackers, and CyberPress.
  • Microsoft subsequently patched the underlying recursive directory-scanning behavior despite the initial triage decision (specific KB/build/date undisclosed).
  • Researchers reported the issue to Microsoft; the ticket was initially closed with the explanation that 'bypassing Defender is not crossing a security boundary.'
  • Varonis validated the technique against Windows Defender, confirming recursive folder scans hang and leave co-located files unscanned.
  • Varonis Threat Labs (researcher Dolev Taler) publicly disclosed the GhostTree / GhostBranch NTFS-junction evasion technique.

Sources cited for GhostTree / GhostBranch

Detection coverage for TL-2026-0821

As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0821 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats