NUMOZYLOD Malware Exploits MSIX Installers for Dangerous Code Execution
ID: a7210374-65d5-5fc7-9aae-2b45db9e2485
STIX ID: report--a7210374-65d5-5fc7-9aae-2b45db9e2485
Feed Name: Cyber Press
Recent campaigns attributed to UNC4536 distribute trojanized MSIX installers via malvertising; these packages use the Package Support Framework to run a PowerShell wrapper (NUMOZYLOD/Refresh2.ps1) which disables security controls, downloads secondary payloads (including CARBANAK and LUMMASTEALER), and uses techniques such as runFullTrust, DLL search-order hijacking, and multi-layer obfuscation to evade detection. The activity reflects MaaS-style operations supplying varied malware to criminal partners and highlights detection opportunities around MSIX artifacts, unusual PowerShell execution, VFS interactions, and AMSI/ScriptBlock logging anomalies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
