Cofense Intelligence exposes how threat actors abuse Windows File Explorer and WebDAV servers to bypass browser security and push RATs to corporate targets. ThreatCofense Intelligence exposes how threat actors abuse Windows File Explorer and WebDAV servers to bypass browser security and push RATs to corporate targets. Threat

RAT Malware Via Windows Explorer Puts Crypto at Risk

2026/03/02 06:00
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Cofense Intelligence exposes how threat actors abuse Windows File Explorer and WebDAV servers to bypass browser security and push RATs to corporate targets.

Threat actors have found a way to push malware directly onto corporate machines without going through a web browser at all. Cofense Intelligence published findings on February 25, 2026, revealing an active campaign that weaponizes Windows File Explorer’s built-in ability to connect to remote WebDAV servers. The tactic sidesteps standard browser download warnings entirely. Most users have no idea that File Explorer can reach out to internet servers.

WebDAV is an old HTTP-based file management protocol. Few people use it today. But Windows still supports it natively inside File Explorer, even though Microsoft deprecated the feature in November 2023. That gap between deprecation and full removal is exactly what attackers are walking through.

When a Folder Is Not Really a Folder

According to Cofense Intelligence in their published report, campaign volume first appeared in February 2024, then spiked sharply in September 2024. It has remained active ever since. The attacks have not slowed. 87 percent of all Active Threat Reports tied to this tactic deliver multiple remote access trojans as final payloads. XWorm RAT, Async RAT, and DcRAT show up most often.

Must Read: Crypto Security Breach: January Hacks Total $86M, Phishing Skyrockets

How the Attack Actually Works

Victims receive phishing emails, often disguised as invoices in German. The emails carry either URL shortcut files (.url) or LNK shortcut files (.lnk). Both can silently open a WebDAV connection inside File Explorer. The user sees what looks like a local folder. It is not.

What makes this particularly damaging is the chain that follows. Scripts pull down additional scripts from separate WebDAV servers. Legitimate files mix in with malicious ones to blur detection. By the time a RAT lands, the delivery path has passed through several layers of obfuscation. Security tools that scan browser downloads miss the whole sequence.

The Cofense report notes that 50% of all affected campaigns are in German. English-language campaigns account for 30%. Italian and Spanish make up the rest. That split points directly at European corporate email accounts as the primary target pool.

You Might Also Like: npm Worm Steals Crypto Keys, Targets 19 Packages

Cloudflare Tunnel is doing heavy lifting for the attackers here. All ATRs tied to this tactic use free demo accounts on trycloudflare[.]com to host the malicious WebDAV servers. Cloudflare’s own infrastructure routes the victim’s connection. That makes the traffic look legitimate on first inspection. The demo accounts are short-lived by design, so threat actors pull them down fast after campaigns go active, cutting off forensic analysis.

Why Crypto Holders Face Serious Exposure

This is where it gets dangerous for anyone holding digital assets. RATs like XWorm and Async RAT give attackers persistent, remote access to an infected machine. That means clipboard contents, browser sessions, saved passwords, and crypto wallet files all sit within reach. Clipboard hijacking, a method already linked to hundreds of millions in crypto theft, becomes trivial once a RAT is running.

Phishing losses alone exceeded $300 million in January 2026, according to security tracking data. That figure dwarfs protocol hack losses in the same period. The attack methods documented by Cofense feed directly into that pipeline. A RAT dropped via WebDAV on a finance team employee’s machine is not just a corporate IT problem. It is a direct path to drained wallets and stolen keys.

Also Worth Your Attention: As Threats Increase, Crypto Wallet Security Will Be A Top Priority In 2026

What Organizations Need to Do Now

The Cofense report recommends hunting for network traffic to Cloudflare Tunnel demo instances specifically. EDR tools with behavioral analysis should flag.URL and .LNK files that reach out to remote servers. The harder fix is user education. Most people simply do not know that File Explorer’s address bar works like a browser.

Checking it the same way they would check a suspicious URL is the first line of defense. Similar abuse is possible through FTP and SMB. Both protocols see regular enterprise use, and both can reach external servers. The attack surface Cofense is documenting is wider than just WebDAV.

Related: Hacks and Security Incidents in 2025: A Year That Exposed Crypto’s Weakest Links

The full technical breakdown, including IOC tables and Cloudflare Tunnel domain examples tied to specific Active Threat Reports, is available in the Cofense Intelligence report published at cofense.com.

The post RAT Malware Via Windows Explorer Puts Crypto at Risk appeared first on Live Bitcoin News.

Market Opportunity
Rats Logo
Rats Price(RATS)
$0.00004562
$0.00004562$0.00004562
+1.19%
USD
Rats (RATS) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

USDH Power Struggle Ignites Stablecoin “Bidding Wars” Across DeFi: Bloomberg

USDH Power Struggle Ignites Stablecoin “Bidding Wars” Across DeFi: Bloomberg

A heated contest for control over a new dollar-pegged token has set the stage for what analysts say could define the next phase of the stablecoin industry. According to Bloomberg, a bidding war unfolded on Hyperliquid, one of crypto’s fastest-growing trading platforms, with the prize being the right to issue USDH, its native stablecoin. The competition drew some of the sector’s most prominent names, including Paxos, Sky, and Ethena, who later withdrew their bid, alongside the lesser-known Native Markets, a startup backed by Stripe stablecoin subsidiary Bridge. Hyperliquid Stablecoin Race Shows Branding and Partnerships Matter as Much as Tech Over the weekend, Hyperliquid’s validators, the contributors who secure the network and vote on key decisions, awarded the USDH contract to Native Markets over the weekend. Despite its relatively new status, the firm’s connection with Stripe helped it outpace more established rivals. Stablecoins underpin decentralized finance by providing a dollar-backed medium for collateral, settlement, and payments across applications. What began as a grassroots, community-led sector has evolved into a battleground for institutions and payment companies seeking revenue from interest on reserves. Circle, for example, shares proceeds from its USDC with Coinbase under a partnership designed to stabilize earnings during market swings. The Hyperliquid contest offered a rare glimpse into just how intense competition has become. Paxos pledged to take no revenue until USDH surpassed $1 billion in circulation. Agora offered to share 100% of net revenue with Hyperliquid, while Ethena put forward 95%. All were outbid by Native Markets, whose ties to Stripe’s $1.1 billion acquisition of Bridge and subsequent rollout of the Tempo blockchain positioned it as a strong contender. “Every stablecoin issuer is extremely desperate for supply,” said Zaheer Ebtikar, co-founder of Split Capital. “They are willing to publicly announce how much they are willing to offer. It just shows it’s a very tough business for stablecoin issuers.” While USDC remains dominant on Hyperliquid with more than $5.6 billion in deposits, the arrival of USDH could shift flows and revenue dynamics. Paxos co-founder Bhau Kotecha said the firm sees the exchange’s growth as an important opportunity, while Agora’s co-founder Nick van Eck warned that awarding the contract to a vertically integrated issuer risked undermining decentralization. Regulatory positioning also factored into the debate. Paxos operates under a New York trust charter and is seeking a federal license, while Bridge holds money transmitter approvals in 30 states. Native Markets, in a blog post, cited regulatory flexibility and deployment speed as reasons for its selection. Hyperliquid said the strong engagement from its community validated the process. Circle CEO Jeremy Allaire dismissed concerns over USDC’s status, noting on X that competition benefits the ecosystem. Analysts suggested that fears of centralization may be exaggerated, noting that Hyperliquid is likely to remain neutral and support multiple stablecoins. Still, the contest over USDH highlighted a new reality for stablecoins: branding, partnerships, and business strategy are becoming as decisive as technology. Native Markets Secures USDH Stablecoin Mandate on Hyperliquid Hyperliquid has concluded its governance vote for the USDH stablecoin, awarding the mandate to Native Markets after a closely watched process that drew weeks of community debate and rival proposals. USDH, described by Hyperliquid as a “Hyperliquid-first, compliant, and natively minted” dollar-backed token, is intended to reduce the platform’s dependence on USDC and strengthen its spot markets. Validators on the decentralized exchange voted in favor of Native Markets, a relatively new player backed by Stripe’s Bridge subsidiary, over established contenders including Paxos and Ethena. The outcome followed a string of proposals offering aggressive revenue-sharing terms to win validator support, underscoring the scale of incentives attached to controlling USDH. Hyperliquid’s exchange has become a critical hub for stablecoin liquidity, with $5.7 billion in USDC, around 8% of its total supply, currently held on the network. At prevailing treasury yields, that translates to an estimated $200 million to $220 million in annual revenue for Circle, underlining why a native alternative could be transformative. Hyperliquid’s validators, who secure the network and vote on key decisions, selected Native Markets following an on-chain governance process that concluded September 15. Native Markets has laid out a phased rollout for USDH, beginning with capped minting and redemption trials before expanding into spot markets. Its reserves will be managed in cash and treasuries by BlackRock, with on-chain tokenization through Superstate and Bridge. Yield from those reserves will be split between Hyperliquid’s Assistance Fund and ecosystem development. The launch of USDH comes as Hyperliquid records record profits from perpetual futures trading, with $106 million in revenue in August alone, and prepares to slash spot trading fees by 80% to bolster liquidity. Analysts say the move positions Hyperliquid to capture more of the stablecoin economics internally, marking a significant step in its bid to rival the largest players in decentralized finance
Share
CryptoNews2025/09/18 00:48
Bitcoin Market Faces Renewed Pressure: What Lies Ahead?

Bitcoin Market Faces Renewed Pressure: What Lies Ahead?

The post Bitcoin Market Faces Renewed Pressure: What Lies Ahead? appeared on BitcoinEthereumNews.com. Recent data reveals heightened instability in the cryptocurrency
Share
BitcoinEthereumNews2026/03/31 01:21
BTC fell below $67,000, down 0.94% on the day.

BTC fell below $67,000, down 0.94% on the day.

PANews reported on March 31 that, according to OKX market data, BTC has just fallen below $67,000 and is currently trading at $66,989.20 per coin, down 0.94% on
Share
PANews2026/03/31 01:22