<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[StucxTeam Forum - Malware]]></title>
		<link>https://stucxteam.my/</link>
		<description><![CDATA[StucxTeam Forum - https://stucxteam.my]]></description>
		<pubDate>Sun, 02 Aug 2026 06:20:23 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Hackers Exploit Windows File Explorer and WebDAV to Distribute Malware]]></title>
			<link>https://stucxteam.my/Thread-news-hackers-exploit-windows-file-explorer-and-webdav-to-distribute-malware</link>
			<pubDate>Sun, 01 Mar 2026 10:00:30 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://stucxteam.my/member.php?action=profile&uid=14">DeRosa</a>]]></dc:creator>
			<guid isPermaLink="false">https://stucxteam.my/Thread-news-hackers-exploit-windows-file-explorer-and-webdav-to-distribute-malware</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align">
<img src="https://i.imgur.com/EAnZjmP.jpeg" loading="lazy"  width="1600" height="900" alt="[Image: EAnZjmP.jpeg]" class="mycode_img" /></div>
<br />
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Cybersecurity researchers at Cofense Intelligence have uncovered an ongoing campaign where threat actors abuse Windows File Explorer to distribute malware.</span></span></div>
<span style="font-weight: bold;" class="mycode_b"><span style="font-family: Poppins;" class="mycode_font"><span style="color: #ffffff;" class="mycode_color">By exploiting the legacy WebDAV protocol, attackers are tricking victims into downloading</span><span style="color: #131f49;" class="mycode_color"> </span></span><a href="https://gbhackers.com/hackers-exploit-cloudflare-tunnel-infrastructure/" target="_blank" rel="noopener" class="mycode_url"><span style="color: #e52e2e;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Remote Access Trojans (RATs) </span></span></a><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">while bypassing traditional web browser security controls and some Endpoint Detection and Response (EDR) systems.</span><br />
</span><br />
<br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-size: x-large;" class="mycode_size">WebDAV Exploit</span><br />
<br />
<span style="font-size: x-small;" class="mycode_size">WebDAV (Web-based Distributed Authoring and Versioning) is an HTTP-based file management protocol.</span></span></span></span><br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-size: x-small;" class="mycode_size">Although Microsoft deprecated it in November 2023, it remains natively supported within Windows File Explorer.</span></span></span></span><br />
<br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-size: x-small;" class="mycode_size">Attackers exploit this by sending malicious links that open remote WebDAV servers directly within File Explorer.</span></span></span></span><br />
<br />
<span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="color: #ffffff;" class="mycode_color"><span style="font-size: x-small;" class="mycode_size">Because the interface looks like a standard local folder, victims are less suspicious of the files they are viewing.</span></span></span></span><br />
<br />
<br />
<br />
<img src="https://gbhackers.com/wp-content/uploads/2026/02/image-94.png" loading="lazy"  width="775" height="393" alt="[Image: image-94.png]" class="mycode_img" /><br />
<span style="font-family: PT Serif;" class="mycode_font"><span style="font-style: italic;" class="mycode_i"><span style="font-weight: bold;" class="mycode_b"><span style="color: #ffff44;" class="mycode_color">Windows File Explorer connected to a WebDAV server hosted on module-brush-sort-factory[.]trycloudflare[.]com. (Source: Cofense)<br />
</span><br />
</span></span></span> <br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Threat actors primarily use three methods to execute this attack: Direct Linking <br />
(using </span>file:// <span style="font-family: Poppins;" class="mycode_font">URIs), URL shortcut files (</span>.url<span style="font-family: Poppins;" class="mycode_font">), and LNK shortcut files (</span>.lnk<span style="font-family: Poppins;" class="mycode_font">).</span></span><br />
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">These files directly open remote paths or<a href="https://gbhackers.com/researchers-jailbreaked-deepseek-r1/" target="_blank" rel="noopener" class="mycode_url"> run malicious scripts from the attacker’s server</a>. </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Interestingly, if a </span>.url <span style="font-family: Poppins;" class="mycode_font">file contains a Windows UNC path, simply opening the local folder </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">containing the shortcut triggers an automatic DNS lookup.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">This inadvertently alerts the attacker that the payload is active on a victim’s machine.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #131f49;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><a href="https://cofense.com/blog/abusing-windows-file-explorer-and-webdav-for-malware-delivery" target="_blank" rel="noopener" class="mycode_url">[/url]<br />
</span></span><br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">To hide their malicious activities, attackers are heavily relying on free demo instances of Cloudflare Tunnels (</span><span style="font-family: Poppins;" class="mycode_font">trycloudflare[.]com </span><span style="font-family: Poppins;" class="mycode_font">) to host their WebDAV servers.</span><br />
<br />
<span style="font-family: Poppins;" class="mycode_font">When a victim connects to the malicious WebDAV server, their network traffic is routed through legitimate Cloudflare infrastructure.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #131f49;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><img src="https://gbhackers.com/wp-content/uploads/2026/02/image-93.png" loading="lazy"  width="924" height="224" alt="[Image: image-93.png]" class="mycode_img" /></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">This makes detection difficult for security analysts who might dismiss the traffic as safe. Furthermore, these servers are short-lived, which prevents security researchers from analyzing the payloads after the campaign concludes.</span> </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[b][b]<span style="font-size: large;" class="mycode_size"><span style="font-family: Arial Black;" class="mycode_font">Malware Payloads and Targeted Victims</span></span></span>[/b][/b]</span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[b][b]<span style="font-family: Arial Black;" class="mycode_font">[url=https://cofense.com/blog/abusing-windows-file-explorer-and-webdav-for-malware-delivery]<span style="font-family: Poppins;" class="mycode_font">According to Cofense</span></a><span style="font-family: Poppins;" class="mycode_font">, this tactic has been observed since February 2024, but campaign volume surged significantly in September 2024.</span> </span></span>[/b][/b]</span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[b]<span style="font-family: Arial Black;" class="mycode_font"><span style="font-family: Poppins;" class="mycode_font">The primary payload for 87% of these attacks is multiple remote access trojans (RATs) delivered simultaneously. </span></span></span>[/b]</span></div>
<div style="text-align: left;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">The most popular malware families deployed in these attacks include XWorm RAT, Async RAT, and DcRAT. </span></span></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #131f49;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-family: Poppins;" class="mycode_font"><img src="https://gbhackers.com/wp-content/uploads/2026/02/image-92.png" loading="lazy"  width="808" height="498" alt="[Image: image-92.png]" class="mycode_img" /></span></span></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #131f49;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><span style="font-size: x-small;" class="mycode_size"><span style="font-style: italic;" class="mycode_i"><span style="color: #999999;" class="mycode_color"><span style="font-family: PT Serif;" class="mycode_font">Windows File Explorer is by default configured to provide a message to confirm whether the file is intended to be run.</span></span></span><span style="color: #999999;" class="mycode_color"><span style="font-family: PT Serif;" class="mycode_font"><span style="font-style: italic;" class="mycode_i"> (Source: Cofense)</span></span></span></span> </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">The campaigns largely target European corporate networks through phishing emails. </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Currently, 50% of the active threat reports associated with this tactic use German language emails featuring fake financial invoices, while another 30% utilize English language lures. </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">[b]Indicators of Compromise (IOCs)</span>[/b]</span></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Poppins;" class="mycode_font">The following </span><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTcpGmjTqz3CzAMsYQRrL3u4j64UfB06qpwMhXbzfxT5E6zOKyCLjDfrevj9wm8uyH8Ar9T0Z1sfgjVCiDjaE6912kJJNPV8KlpLrRuRjOhcl20dThlF2N_FjENmH9eQMuwLjop7kM-A3FDNUbAXPwF1Y_mVKrMo8xpwz6-m-RGT60vQ9Ll7l-6VUo-9Y/s16000/Firewalls.webp" target="_blank" rel="noopener" class="mycode_url"><span style="font-family: Poppins;" class="mycode_font">Cloudflare Tunnel domains </span></a><span style="font-family: Poppins;" class="mycode_font">have been observed hosting malicious WebDAV servers in recent campaigns. Security teams should monitor for unusual outbound traffic to these addresses.</span></span></span></span></div>
<div style="text-align: left;" class="mycode_align">
<br />
<br />
<span style="color: #131f49;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><img src="https://i.imgur.com/30zgHqq.png" loading="lazy"  width="762" height="450" alt="[Image: 30zgHqq.png]" class="mycode_img" /></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="font-family: Poppins;" class="mycode_font"><span style="color: #ffffff;" class="mycode_color">Organizations should consider disabling</span><a href="https://gbhackers.com/webdav-malicious-file-malware-attacks/" target="_blank" rel="noopener" class="mycode_url"><span style="color: #131f49;" class="mycode_color"><span style="color: #e52e2e;" class="mycode_color"> WebDAV client services</span></span></a><span style="color: #131f49;" class="mycode_color"> </span><span style="color: #ffffff;" class="mycode_color">if they are not actively required for business operations.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="font-family: Poppins;" class="mycode_font"><br />
<span style="color: #ffffff;" class="mycode_color">Additionally, IT teams must monitor for unusual outbound SMB or WebDAV traffic, particularly connections attempting to access unauthorized internet resources via File Explorer.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Similar networking protocols like FTP and CIFS can also be abused using these same methods, so holistic network monitoring is essential. </span></span></div>]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align">
<img src="https://i.imgur.com/EAnZjmP.jpeg" loading="lazy"  width="1600" height="900" alt="[Image: EAnZjmP.jpeg]" class="mycode_img" /></div>
<br />
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Cybersecurity researchers at Cofense Intelligence have uncovered an ongoing campaign where threat actors abuse Windows File Explorer to distribute malware.</span></span></div>
<span style="font-weight: bold;" class="mycode_b"><span style="font-family: Poppins;" class="mycode_font"><span style="color: #ffffff;" class="mycode_color">By exploiting the legacy WebDAV protocol, attackers are tricking victims into downloading</span><span style="color: #131f49;" class="mycode_color"> </span></span><a href="https://gbhackers.com/hackers-exploit-cloudflare-tunnel-infrastructure/" target="_blank" rel="noopener" class="mycode_url"><span style="color: #e52e2e;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Remote Access Trojans (RATs) </span></span></a><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">while bypassing traditional web browser security controls and some Endpoint Detection and Response (EDR) systems.</span><br />
</span><br />
<br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-size: x-large;" class="mycode_size">WebDAV Exploit</span><br />
<br />
<span style="font-size: x-small;" class="mycode_size">WebDAV (Web-based Distributed Authoring and Versioning) is an HTTP-based file management protocol.</span></span></span></span><br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-size: x-small;" class="mycode_size">Although Microsoft deprecated it in November 2023, it remains natively supported within Windows File Explorer.</span></span></span></span><br />
<br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-size: x-small;" class="mycode_size">Attackers exploit this by sending malicious links that open remote WebDAV servers directly within File Explorer.</span></span></span></span><br />
<br />
<span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="color: #ffffff;" class="mycode_color"><span style="font-size: x-small;" class="mycode_size">Because the interface looks like a standard local folder, victims are less suspicious of the files they are viewing.</span></span></span></span><br />
<br />
<br />
<br />
<img src="https://gbhackers.com/wp-content/uploads/2026/02/image-94.png" loading="lazy"  width="775" height="393" alt="[Image: image-94.png]" class="mycode_img" /><br />
<span style="font-family: PT Serif;" class="mycode_font"><span style="font-style: italic;" class="mycode_i"><span style="font-weight: bold;" class="mycode_b"><span style="color: #ffff44;" class="mycode_color">Windows File Explorer connected to a WebDAV server hosted on module-brush-sort-factory[.]trycloudflare[.]com. (Source: Cofense)<br />
</span><br />
</span></span></span> <br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Threat actors primarily use three methods to execute this attack: Direct Linking <br />
(using </span>file:// <span style="font-family: Poppins;" class="mycode_font">URIs), URL shortcut files (</span>.url<span style="font-family: Poppins;" class="mycode_font">), and LNK shortcut files (</span>.lnk<span style="font-family: Poppins;" class="mycode_font">).</span></span><br />
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">These files directly open remote paths or<a href="https://gbhackers.com/researchers-jailbreaked-deepseek-r1/" target="_blank" rel="noopener" class="mycode_url"> run malicious scripts from the attacker’s server</a>. </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Interestingly, if a </span>.url <span style="font-family: Poppins;" class="mycode_font">file contains a Windows UNC path, simply opening the local folder </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">containing the shortcut triggers an automatic DNS lookup.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">This inadvertently alerts the attacker that the payload is active on a victim’s machine.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #131f49;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><a href="https://cofense.com/blog/abusing-windows-file-explorer-and-webdav-for-malware-delivery" target="_blank" rel="noopener" class="mycode_url">[/url]<br />
</span></span><br />
<span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">To hide their malicious activities, attackers are heavily relying on free demo instances of Cloudflare Tunnels (</span><span style="font-family: Poppins;" class="mycode_font">trycloudflare[.]com </span><span style="font-family: Poppins;" class="mycode_font">) to host their WebDAV servers.</span><br />
<br />
<span style="font-family: Poppins;" class="mycode_font">When a victim connects to the malicious WebDAV server, their network traffic is routed through legitimate Cloudflare infrastructure.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #131f49;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><img src="https://gbhackers.com/wp-content/uploads/2026/02/image-93.png" loading="lazy"  width="924" height="224" alt="[Image: image-93.png]" class="mycode_img" /></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">This makes detection difficult for security analysts who might dismiss the traffic as safe. Furthermore, these servers are short-lived, which prevents security researchers from analyzing the payloads after the campaign concludes.</span> </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[b][b]<span style="font-size: large;" class="mycode_size"><span style="font-family: Arial Black;" class="mycode_font">Malware Payloads and Targeted Victims</span></span></span>[/b][/b]</span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[b][b]<span style="font-family: Arial Black;" class="mycode_font">[url=https://cofense.com/blog/abusing-windows-file-explorer-and-webdav-for-malware-delivery]<span style="font-family: Poppins;" class="mycode_font">According to Cofense</span></a><span style="font-family: Poppins;" class="mycode_font">, this tactic has been observed since February 2024, but campaign volume surged significantly in September 2024.</span> </span></span>[/b][/b]</span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">[b]<span style="font-family: Arial Black;" class="mycode_font"><span style="font-family: Poppins;" class="mycode_font">The primary payload for 87% of these attacks is multiple remote access trojans (RATs) delivered simultaneously. </span></span></span>[/b]</span></div>
<div style="text-align: left;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">The most popular malware families deployed in these attacks include XWorm RAT, Async RAT, and DcRAT. </span></span></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #131f49;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-family: Poppins;" class="mycode_font"><img src="https://gbhackers.com/wp-content/uploads/2026/02/image-92.png" loading="lazy"  width="808" height="498" alt="[Image: image-92.png]" class="mycode_img" /></span></span></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #131f49;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><span style="font-size: x-small;" class="mycode_size"><span style="font-style: italic;" class="mycode_i"><span style="color: #999999;" class="mycode_color"><span style="font-family: PT Serif;" class="mycode_font">Windows File Explorer is by default configured to provide a message to confirm whether the file is intended to be run.</span></span></span><span style="color: #999999;" class="mycode_color"><span style="font-family: PT Serif;" class="mycode_font"><span style="font-style: italic;" class="mycode_i"> (Source: Cofense)</span></span></span></span> </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">The campaigns largely target European corporate networks through phishing emails. </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Currently, 50% of the active threat reports associated with this tactic use German language emails featuring fake financial invoices, while another 30% utilize English language lures. </span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-size: large;" class="mycode_size"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b">[b]Indicators of Compromise (IOCs)</span>[/b]</span></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Arial Black;" class="mycode_font"><span style="font-weight: bold;" class="mycode_b"><span style="font-family: Poppins;" class="mycode_font">The following </span><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTcpGmjTqz3CzAMsYQRrL3u4j64UfB06qpwMhXbzfxT5E6zOKyCLjDfrevj9wm8uyH8Ar9T0Z1sfgjVCiDjaE6912kJJNPV8KlpLrRuRjOhcl20dThlF2N_FjENmH9eQMuwLjop7kM-A3FDNUbAXPwF1Y_mVKrMo8xpwz6-m-RGT60vQ9Ll7l-6VUo-9Y/s16000/Firewalls.webp" target="_blank" rel="noopener" class="mycode_url"><span style="font-family: Poppins;" class="mycode_font">Cloudflare Tunnel domains </span></a><span style="font-family: Poppins;" class="mycode_font">have been observed hosting malicious WebDAV servers in recent campaigns. Security teams should monitor for unusual outbound traffic to these addresses.</span></span></span></span></div>
<div style="text-align: left;" class="mycode_align">
<br />
<br />
<span style="color: #131f49;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font"><img src="https://i.imgur.com/30zgHqq.png" loading="lazy"  width="762" height="450" alt="[Image: 30zgHqq.png]" class="mycode_img" /></span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="font-family: Poppins;" class="mycode_font"><span style="color: #ffffff;" class="mycode_color">Organizations should consider disabling</span><a href="https://gbhackers.com/webdav-malicious-file-malware-attacks/" target="_blank" rel="noopener" class="mycode_url"><span style="color: #131f49;" class="mycode_color"><span style="color: #e52e2e;" class="mycode_color"> WebDAV client services</span></span></a><span style="color: #131f49;" class="mycode_color"> </span><span style="color: #ffffff;" class="mycode_color">if they are not actively required for business operations.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="font-family: Poppins;" class="mycode_font"><br />
<span style="color: #ffffff;" class="mycode_color">Additionally, IT teams must monitor for unusual outbound SMB or WebDAV traffic, particularly connections attempting to access unauthorized internet resources via File Explorer.</span></span></div>
<div style="text-align: left;" class="mycode_align"><span style="color: #ffffff;" class="mycode_color"><span style="font-family: Poppins;" class="mycode_font">Similar networking protocols like FTP and CIFS can also be abused using these same methods, so holistic network monitoring is essential. </span></span></div>]]></content:encoded>
		</item>
	</channel>
</rss>