Microsoft Disables MSIX App Installer Protocol Widely Used in Malware Attacks
ID: eb1a1dc5-ae18-5e18-b539-2f4b8050da1f
STIX ID: report--eb1a1dc5-ae18-5e18-b539-2f4b8050da1f
Feed Name: The Hacker News
Microsoft disabled the ms-appinstaller protocol handler after multiple financially motivated threat actors abused signed MSIX application packages distributed via Teams, malicious ads and SEO-poisoned sites to deliver loaders (EugenLoader/BATLOADER/GHOSTPULSE), stealers, RATs (NetSupport, SectopRAT, DarkGate) and facilitate human-operated ransomware (Black Basta and others); several initial access brokers and criminal groups (Storm-0569, Storm-1113, Sangria Tempest/FIN7, Storm-1674) have been observed using and selling malicious installers and landing-page frameworks since mid-2023.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
