Advanced Persistent Threats (APTs) pose one of the most significant challenges in cyberspace security. They are characterized by stealthy and sustained efforts to steal high-value files from the endpoint devices of key personnel. Existing APT detection and defense approaches perform exhaustive system log analysis to identify suspicious event indicators, but lack the capability to safeguard data assets on compromised endpoints. Moreover, persistently exploring the complete attack process while eliminating potential file damage remains a fundamental challenge. This paper presents TRAPShield, a novel APT file theft defense framework that directly targets the ultimate goal of the attack, enabling effective protection of critical files. TRAPShield identifies malicious access to sensitive files through multi-granularity, multi-domain behavioral characterization, combined with an adaptive identity authentication mechanism. It transparently intercepts malicious accesses and redirects them to highly similar deceptive decoy files. By leveraging contextual information around decoy-triggering points, TRAPShield enables continuous tracking of the entire attack campaign without file leakage. We conduct extensive experiments on four groups of datasets constructed in controlled environments and real operational endpoints, covering diverse APT file theft modalities disclosed in large-scale APT reports. Results demonstrate that TRAPShield achieves $F_{1}$ scores exceeding 90.95% in identifying file theft behaviors, and maintains zero false negative rates with authentication required for less than 5% of accesses. For malicious accesses, TRAPShield misguides them to decoys in an average of 0.125 ms, preventing the exfiltration of actual sensitive contents in real-time. Furthermore, it comprehensively tracks and reconstructs all attack scenarios and captures multi-stage malware artifacts, providing vital evidence for forensic investigation and threat attribution.
