logo

Financially motivated threat actors misusing App Installer

ID: cb8842b0-c490-5179-a36d-1a488268182b

STIX ID: report--cb8842b0-c490-5179-a36d-1a488268182b

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2023-12-28

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence observed since mid-November 2023 multiple financially motivated groups abusing the ms-appinstaller URI scheme and signed MSIX packages distributed via malvertising, SEO poisoning, and Microsoft Teams phishing to install loaders (BATLOADER, EugenLoader), backdoors (Carbanak, Gracewire), info-stealers, and ultimately enable ransomware (Black Basta, Clop); the report provides technical details, IOCs (hashes, domains, URLs), hunting queries, detections, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.