logo

NUMOZYLOD Malware Exploits MSIX Installers for Dangerous Code Execution

ID: a7210374-65d5-5fc7-9aae-2b45db9e2485

STIX ID: report--a7210374-65d5-5fc7-9aae-2b45db9e2485

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2024-08-21

Date Updated: 2026-04-19

Author: Kaaviya

...
...

Recent campaigns attributed to UNC4536 distribute trojanized MSIX installers via malvertising; these packages use the Package Support Framework to run a PowerShell wrapper (NUMOZYLOD/Refresh2.ps1) which disables security controls, downloads secondary payloads (including CARBANAK and LUMMASTEALER), and uses techniques such as runFullTrust, DLL search-order hijacking, and multi-layer obfuscation to evade detection. The activity reflects MaaS-style operations supplying varied malware to criminal partners and highlights detection opportunities around MSIX artifacts, unusual PowerShell execution, VFS interactions, and AMSI/ScriptBlock logging anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.