logo

Microsoft Disables App Installer After Feature is Abused for Malware

ID: 8a0500ac-4139-5c42-834f-9b72ef5ae9c3

STIX ID: report--8a0500ac-4139-5c42-834f-9b72ef5ae9c3

Feed Name: HackRead

Threat Score
72/100

Date Published: 2023-12-31

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Microsoft disabled the ms-appinstaller URI scheme after Microsoft Threat Intelligence observed financially motivated threat actors abusing the App Installer/MSIX handler to distribute signed malicious packages via deceptive search ads, SEO poisoning and phishing, delivering loaders, stealers, RATs and other malware families; Microsoft issued an update (addressing CVE-2021-43890) to disable the handler by default and recommends phishing-resistant authentication and user education to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.