RAT Malware Exploits Windows Explorer, Threatens Crypto

04 Mar 2026

Cofense Intelligence has uncovered a sophisticated malware campaign exploiting Windows File Explorer and WebDAV servers to deploy remote access trojans (RATs) directly onto corporate systems, bypassing traditional browser security measures. The findings, published on 2026-02-25, highlight a significant threat to organizations, particularly those dealing with cryptocurrency.

Exploiting Windows Explorer and WebDAV

Threat actors have leveraged the deprecated yet still functional WebDAV protocol within Windows File Explorer to bypass browser download warnings. This tactic, active since February 2024 and peaking in September 2024, involves phishing emails disguised as invoices, primarily targeting European corporations. These emails contain URL or LNK shortcut files that silently open WebDAV connections, allowing the download of malicious files alongside legitimate ones.

Impact on Cryptocurrency Security

The RATs deployed, including XWorm RAT and Async RAT, provide attackers with persistent access to infected machines, enabling them to steal clipboard contents, browser sessions, saved passwords, and crypto wallet files. This has led to significant financial losses, with phishing-related thefts exceeding $300 million in January 2026 alone. The use of Cloudflare Tunnel accounts further obscures malicious activity, complicating forensic investigations.

Mitigation Strategies for Organizations

Cofense advises organizations to monitor network traffic for Cloudflare Tunnel demo instances and employ EDR behavioral analysis to detect suspicious .URL and .LNK files. User education is crucial, as employees should treat File Explorer links with the same caution as suspicious URLs. The attack surface extends beyond WebDAV, with potential abuse via FTP and SMB protocols.

For a detailed technical breakdown, including indicators of compromise and specific domain examples, refer to the full Cofense Intelligence report available at cofense.com.

The Rats in the Wall

The Rats in the Wall download for free to PC or mobile

Explore a haunting mansion, uncover hidden truths, and unravel a chilling family mystery.

4
1030 reviews
2374 downloads

News and reviews about The Rats in the Wall

12 May 2025

Nier Collaboration Enhances The First Descendant's Appeal

Nier Automata fans rejoice as a new collaboration brings iconic 2B to The First Descendant, highlighting Nexon's dedication to enhance their gaming experience.

Read more

10 May 2025

Nexon Prepares for The First Descendant Season 3 Updates

Nexon is prioritizing major updates for The First Descendant's upcoming Season 3, focusing on balance and quality improvements as players anticipate new features and enhancements.

Read more

14 Apr 2025

Descendant: Nexon's Update Enhances Endgame Rewards

Nexon's hotfix for The First Descendant increases rewards in the Void Erosion Purge mode, easing restrictions and enhancing gameplay. The update aims to balance challenges and visual effects, broadening player engagement with augmented crafting materials.

Read more

09 Apr 2025

The First Descendant Faces Opposition After Latest Nerfs

Nexon's The First Descendant sees player decline and negative reviews on Steam after recent nerfs, contradicting earlier developer assurances.

Read more

10 Jul 2024

The First Descendant by Nexon Tops Steam Charts, Surpasses Elden Ring

The First Descendant by Nexon has swiftly climbed to the top position on Steam, overtaking well-known games such as Elden Ring and Counter-Strike 2. This rapid ascent highlights the game's growing popularity and strong market presence.

Read more

Comments (0)

No comments yet. Be the first to comment!