Windows defenders are facing a new way for attackers to hide activity after gaining administrator access.
The technique abuses Windows bind links, a legitimate feature that redirects one file path to another without changing the original file on disk.
Rather than dropping a visible replacement file or modifying security software, an attacker can make a trusted path quietly return malicious content.
This creates a gap between what a process runs and what endpoint tools believe they are inspecting.