logo

Microsoft disables MSIX protocol handler abused in malware attacks

ID: 552d2b7e-e51b-5f42-9b65-528a7a1366ee

STIX ID: report--552d2b7e-e51b-5f42-9b65-528a7a1366ee

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2023-12-28

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft disabled the ms-appinstaller (MSIX/App Installer) protocol handler after multiple financially motivated threat actors abused a known AppX Installer spoofing vulnerability (CVE-2021-43890) to deliver signed malicious MSIX packages that bypass SmartScreen and browser protections; observed activity includes distribution of Emotet and BazarLoader and links to ransomware deployment, with Microsoft recommending an App Installer update or disabling the protocol via Group Policy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.