Microsoft Disables App Installer After Feature is Abused for Malware
ID: 8a0500ac-4139-5c42-834f-9b72ef5ae9c3
STIX ID: report--8a0500ac-4139-5c42-834f-9b72ef5ae9c3
Feed Name: HackRead
Microsoft disabled the ms-appinstaller URI scheme after Microsoft Threat Intelligence observed financially motivated threat actors abusing the App Installer/MSIX handler to distribute signed malicious packages via deceptive search ads, SEO poisoning and phishing, delivering loaders, stealers, RATs and other malware families; Microsoft issued an update (addressing CVE-2021-43890) to disable the handler by default and recommends phishing-resistant authentication and user education to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
