logo

Microsoft Disables MSIX App Installer Protocol Widely Used in Malware Attacks

ID: eb1a1dc5-ae18-5e18-b539-2f4b8050da1f

STIX ID: report--eb1a1dc5-ae18-5e18-b539-2f4b8050da1f

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2023-12-29

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Microsoft disabled the ms-appinstaller protocol handler after multiple financially motivated threat actors abused signed MSIX application packages distributed via Teams, malicious ads and SEO-poisoned sites to deliver loaders (EugenLoader/BATLOADER/GHOSTPULSE), stealers, RATs (NetSupport, SectopRAT, DarkGate) and facilitate human-operated ransomware (Black Basta and others); several initial access brokers and criminal groups (Storm-0569, Storm-1113, Sangria Tempest/FIN7, Storm-1674) have been observed using and selling malicious installers and landing-page frameworks since mid-2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.