Financially motivated threat actors misusing App Installer
ID: cb8842b0-c490-5179-a36d-1a488268182b
STIX ID: report--cb8842b0-c490-5179-a36d-1a488268182b
Feed Name: Microsoft Security
Microsoft Threat Intelligence observed since mid-November 2023 multiple financially motivated groups abusing the ms-appinstaller URI scheme and signed MSIX packages distributed via malvertising, SEO poisoning, and Microsoft Teams phishing to install loaders (BATLOADER, EugenLoader), backdoors (Carbanak, Gracewire), info-stealers, and ultimately enable ransomware (Black Basta, Clop); the report provides technical details, IOCs (hashes, domains, URLs), hunting queries, detections, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
