Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Microsoft Security IT

Microsoft Disables MSIX Protocol Handler Abused in Malware Attacks (bleepingcomputer.com) 11

Microsoft has again disabled the MSIX ms-appinstaller protocol handler after multiple financially motivated threat groups abused it to infect Windows users with malware. From a report: The attackers exploited the CVE-2021-43890 Windows AppX Installer spoofing vulnerability to circumvent security measures that would otherwise protect Windows users from malware, such as the Defender SmartScreen anti-phishing and anti-malware component and built-in browser alerts cautioning users against executable file downloads.

Microsoft says the threat actors use both malicious advertisements for popular software and Microsoft Teams phishing messages to push signed malicious MSIX application packages. "Since mid-November 2023, Microsoft Threat Intelligence has observed threat actors, including financially motivated actors like Storm-0569, Storm-1113, Sangria Tempest, and Storm-1674, utilizing the ms-appinstaller URI scheme (App Installer) to distribute malware," the company said.

This discussion has been archived. No new comments can be posted.

Microsoft Disables MSIX Protocol Handler Abused in Malware Attacks

Comments Filter:
  • no shit (Score:5, Funny)

    by TwistedGreen ( 80055 ) on Friday December 29, 2023 @04:30PM (#64115541)

    ms-appinstaller://who-could-have-thought-this-would-be-abused

    • by Dwedit ( 232252 )

      Considering how much trouble and money you have to go though to get an app signed, what's the point of all that stuff when the malware is signed and distributed just as easily?

      • what's the point of all that stuff when the malware is signed and distributed just as easily?

        Someone really needs to look into Windows 11.

      • I always thought Microsoft was so desperate for "apps" that they would let anything onto their Windows Store, so I doubt their review process is comprehensive. They probably just run it through some scanners to make sure it doesn't crash and then call it "certified." It's security theater at best.

        • Why would Microsoft be desperate for apps? Almost every app is made for Windows! Some Linux- and Mac-only apps may not be available, but there's always some equivalent.

          • There was a point where Microsoft would pay you to list your "app" in the Windows Store. There's lots of software available for Windows, but if you actually open their "app store" it's a wasteland of confusing shovelware.

          • Because Microsoft looked at Apple receiving a 30% cut of everything sold in the Apple app store and got insanely jealous. Then they churned out Windows 8 in an attempt to turn everything into an "app" and bring the worst aspects of phone UI to the computer screen. When customers rejected that hot garbage in a pique of common sense, Microsoft knew their app store was a failure and have been desperately trying to figure out a way to make it work since then. They also got the hint and backpedaled on a lot

        • by gweihir ( 88907 )

          It's security theater at best.

          Like basically all "security" in MS products. Even their cloud security is crap and they cannot blame that on legacy stuff.

  • by gweihir ( 88907 ) on Friday December 29, 2023 @06:01PM (#64115703)

    This is another abysmal failure by MS.

Every nonzero finite dimensional inner product space has an orthonormal basis. It makes sense, when you don't think about it.

Working...