Distribution of MSIX Malware Disguised as Notion Installer
ID: 792d3e30-c1cf-536d-bc7a-816eea0d02fa
STIX ID: report--792d3e30-c1cf-536d-bc7a-816eea0d02fa
Feed Name: ASEC
Threat Score
**Executive Summary:** An MSIX installer spoofing the Notion installer, signed with a legitimate certificate and hosted on cloned sites, installs an obfuscated refresh.ps1 which fetches a .NET payload (1.dat) from a C2 (e.g., fleetcontents.com); the .NET payload uses process hollowing to inject LummaC2 into RegAsm.exe, enabling browser, cryptocurrency, and file theft—the report includes MD5 hashes and malicious URLs as IOCs and warns about signed MSIX abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
