Cofense Intelligence exposes how threat actors abuse Windows File Explorer and WebDAV servers to bypass browser security and push RATs to corporate targets. ThreatCofense Intelligence exposes how threat actors abuse Windows File Explorer and WebDAV servers to bypass browser security and push RATs to corporate targets. Threat

RAT Malware Via Windows Explorer Puts Crypto at Risk

2026/03/02 06:00
4 min read
For feedback or concerns regarding this content, please contact us at [email protected]

Cofense Intelligence exposes how threat actors abuse Windows File Explorer and WebDAV servers to bypass browser security and push RATs to corporate targets.

Threat actors have found a way to push malware directly onto corporate machines without going through a web browser at all. Cofense Intelligence published findings on February 25, 2026, revealing an active campaign that weaponizes Windows File Explorer’s built-in ability to connect to remote WebDAV servers. The tactic sidesteps standard browser download warnings entirely. Most users have no idea that File Explorer can reach out to internet servers.

WebDAV is an old HTTP-based file management protocol. Few people use it today. But Windows still supports it natively inside File Explorer, even though Microsoft deprecated the feature in November 2023. That gap between deprecation and full removal is exactly what attackers are walking through.

When a Folder Is Not Really a Folder

According to Cofense Intelligence in their published report, campaign volume first appeared in February 2024, then spiked sharply in September 2024. It has remained active ever since. The attacks have not slowed. 87 percent of all Active Threat Reports tied to this tactic deliver multiple remote access trojans as final payloads. XWorm RAT, Async RAT, and DcRAT show up most often.

Must Read: Crypto Security Breach: January Hacks Total $86M, Phishing Skyrockets

How the Attack Actually Works

Victims receive phishing emails, often disguised as invoices in German. The emails carry either URL shortcut files (.url) or LNK shortcut files (.lnk). Both can silently open a WebDAV connection inside File Explorer. The user sees what looks like a local folder. It is not.

What makes this particularly damaging is the chain that follows. Scripts pull down additional scripts from separate WebDAV servers. Legitimate files mix in with malicious ones to blur detection. By the time a RAT lands, the delivery path has passed through several layers of obfuscation. Security tools that scan browser downloads miss the whole sequence.

The Cofense report notes that 50% of all affected campaigns are in German. English-language campaigns account for 30%. Italian and Spanish make up the rest. That split points directly at European corporate email accounts as the primary target pool.

You Might Also Like: npm Worm Steals Crypto Keys, Targets 19 Packages

Cloudflare Tunnel is doing heavy lifting for the attackers here. All ATRs tied to this tactic use free demo accounts on trycloudflare[.]com to host the malicious WebDAV servers. Cloudflare’s own infrastructure routes the victim’s connection. That makes the traffic look legitimate on first inspection. The demo accounts are short-lived by design, so threat actors pull them down fast after campaigns go active, cutting off forensic analysis.

Why Crypto Holders Face Serious Exposure

This is where it gets dangerous for anyone holding digital assets. RATs like XWorm and Async RAT give attackers persistent, remote access to an infected machine. That means clipboard contents, browser sessions, saved passwords, and crypto wallet files all sit within reach. Clipboard hijacking, a method already linked to hundreds of millions in crypto theft, becomes trivial once a RAT is running.

Phishing losses alone exceeded $300 million in January 2026, according to security tracking data. That figure dwarfs protocol hack losses in the same period. The attack methods documented by Cofense feed directly into that pipeline. A RAT dropped via WebDAV on a finance team employee’s machine is not just a corporate IT problem. It is a direct path to drained wallets and stolen keys.

Also Worth Your Attention: As Threats Increase, Crypto Wallet Security Will Be A Top Priority In 2026

What Organizations Need to Do Now

The Cofense report recommends hunting for network traffic to Cloudflare Tunnel demo instances specifically. EDR tools with behavioral analysis should flag.URL and .LNK files that reach out to remote servers. The harder fix is user education. Most people simply do not know that File Explorer’s address bar works like a browser.

Checking it the same way they would check a suspicious URL is the first line of defense. Similar abuse is possible through FTP and SMB. Both protocols see regular enterprise use, and both can reach external servers. The attack surface Cofense is documenting is wider than just WebDAV.

Related: Hacks and Security Incidents in 2025: A Year That Exposed Crypto’s Weakest Links

The full technical breakdown, including IOC tables and Cloudflare Tunnel domain examples tied to specific Active Threat Reports, is available in the Cofense Intelligence report published at cofense.com.

The post RAT Malware Via Windows Explorer Puts Crypto at Risk appeared first on Live Bitcoin News.

Market Opportunity
Octavia Logo
Octavia Price(VIA)
$0.002969
$0.002969$0.002969
+5.61%
USD
Octavia (VIA) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

iZUMi Finance and Nasdaq-Listed Company CIMG Co-Launch $20M Upstarts Fund

iZUMi Finance and Nasdaq-Listed Company CIMG Co-Launch $20M Upstarts Fund

Singapore, Singapore, 18th September 2025, Chainwire
Share
Blockchainreporter2025/09/18 14:10
Pundit Shares ‘XRP Endgame’: What To Watch Out For With Ripple

Pundit Shares ‘XRP Endgame’: What To Watch Out For With Ripple

Crypto pundit Pumpius is drawing attention to what he calls the “XRP Endgame,” saying all the key pieces are falling into place for Ripple and its token. According to him, these shifts put XRP in a rare position to rise above other digital assets. Global rules and banking standards are also moving in Ripple’s favor at the same time. Pundit: Institutional Rails And Legal Clarity Cement XRP’s Role Pumpius stresses that Ripple’s victory in its long fight with the SEC is not just a legal win but a turning point. After years in court, XRP now has the strongest legal clarity of any cryptocurrency in the U.S.  Related Reading: Market Expert Says XRP Price At $1,000 Will Happen, But The Timeline Is Different He also points to Ripple’s launch of RLUSD, its enterprise stablecoin backed by reserves at BNY Mellon. Pumpius notes that this connection matters because BNY Mellon safeguards trillions in assets for global giants, including BlackRock and the U.S. Treasury. Tying a stablecoin to XRP’s payment rails creates what he calls a “stable reserve army” that strengthens trust in Ripple’s network. On the banking front, Pumpius explains that Ripple is not only licensed as a money service business but has also applied for the highly difficult New York banking charter. He adds that Ripple has taken it a step further by applying for a Federal Reserve master account, the highest privilege in the U.S. banking system. If granted, Ripple would not just compete with banks but effectively act as one, placing XRP at the center of financial settlements. XRP ETFs, Ripple’s Global Standards, And Tech Drive Convergence Pumpius notes that nearly 20 XRP spot ETFs are awaiting approval. If greenlit, these funds could open the doors to trillions of dollars from institutional investors and push XRP into the ranks of Wall Street assets overnight. Another major shift is the migration to ISO 20022, a global messaging standard that all major banks must adhere to by November. Pumpius points out that XRP has been ready for this for years, meaning RippleNet can easily connect with traditional banking rails the moment the change takes effect. Related Reading: Crypto Analyst Debunks XRP Price To $10,000 Claims, Reveals How High It Can Go Additionally, he notes that XRP is in the liquidity tokenization plan of DTCC, the world’s largest settlement utility. At the same time, he notes that the DNA Protocol is quietly developing biometric and genomic identity tools on the XRP Ledger. This step could solve Know Your Customer checks at the deepest level, blending finance and digital identity in a way no other blockchain has achieved. Ripple benefits as he notes the rise of a supportive political environment. A pro-crypto administration is pushing laws that fit Ripple’s long-term playbook. With regulators and policymakers leaning in the same direction, he believes the stage is set for XRP to move into its endgame. Featured image from DALL.E, chart from TradingView.com
Share
NewsBTC2025/09/19 00:00
Tim Draper’s Stark Prediction As Fiat Trust Plummets

Tim Draper’s Stark Prediction As Fiat Trust Plummets

The post Tim Draper’s Stark Prediction As Fiat Trust Plummets appeared on BitcoinEthereumNews.com. Bitcoin Adoption: Tim Draper’s Stark Prediction As Fiat Trust
Share
BitcoinEthereumNews2026/03/14 14:57