Revenue Agenda
  • Investing
  • Latest News
  • Editor’s Pick
  • Economy
  • Investing
  • Latest News
  • Editor’s Pick
  • Economy
No Result
View All Result
Revenue Agenda
No Result
View All Result
Home Economy

Microsoft Takes Action: Why Is it Disabling Key Protocol?

by
January 6, 2024
in Economy
0
Microsoft Takes Action: Why Is it Disabling Key Protocol?
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter
Microsoft Takes Swift Action: Why Is it Disabling Key Protocol?

In response to the escalating threat of malware attacks, the Microsoft Project team has swiftly taken action by disabling the widely abused ms-appinstaller protocol handler. This strategic move is part of Microsoft’s efforts to utilize its cyber threat intelligence tools to counter the alarming exploitation of this protocol by multiple threat actors intent on distributing malware. Ransomware attacks are looming as a significant risk.

Unveiling the Menace

The Microsoft Threat Intelligence team, leveraging advanced cyber threat intelligence tools, uncovered the exploitation of the ms-appinstaller protocol handler as an access vector for malware distribution. As a result, the company decided to disable the protocol handler by default. The company aims to protect users from potential dangers associated with malicious activities.

Malware Microsoft Project: Kit for Sale

Compounding the threat, cybercriminals are actively selling a malware kit as a service, leveraging the MSIX file format and the ms-appinstaller protocol handler. To address this emerging threat, Microsoft implemented changes in the App Installer version 1.21.3421.0 and higher, a testament to the value of effective threat intelligence feeds.

Method of Attack

The attacks orchestrated by at least four financially motivated hacking groups involve the deployment of signed malicious MSIX application packages. The scammers deceptively distribute these packages through trusted channels like Microsoft Teams. They also disguise them as advertisements for legitimate software on search engines like Google.

Diverse Threat Actors in Action

Several hacking groups have been identified exploiting the App Installer service since mid-November 2023. Each employs distinct tactics and underscores the need for robust threat intelligence feeds:

Storm-0569: Uses SEO poisoning with spoofed sites to propagate BATLOADER, deploying Cobalt Strike and Black Basta ransomware. Storm-1113: Distributes EugenLoader disguised as Zoom, serving as an entry point for various stealer malware and remote access trojans. Sangria Tempest (Carbon Spider and FIN7): Leverages Storm-1113’s EugenLoader to drop Carbanak and distribute POWERTRASH through Google ads. Storm-1674: Sends fake landing pages through Teams messages. It also encourages users to download malicious MSIX installers containing SectopRAT or DarkGate payloads.

Microsoft: Persistent Threats and Past Actions

This isn’t the first time Microsoft has disabled the MSIX ms-appinstaller protocol handler. In February 2022, the company has also taken a similar step to thwart Emotet, TrickBot, and Bazaloader delivery. The protocol’s attractiveness to threat actors lies in its ability to circumvent security mechanisms. However, that poses a significant challenge for user safety.

As Microsoft lists its past actions and remains vigilant in combating evolving cybersecurity threats, it urges users to stay informed and employ best practices to enhance their digital security. This includes regular updates, exercising caution with downloads, and staying informed about emerging threats in the ever-evolving landscape of online security, highlighting the importance of cyber threat intelligence tools.

The post Microsoft Takes Action: Why Is it Disabling Key Protocol? appeared first on FinanceBrokerage.

Previous Post

Defense Secretary Lloyd Austin has been hospitalized since Jan. 1

Next Post

Blinken meets with Turkey’s Erdogan as Middle East tensions escalate

Next Post
Blinken meets with Turkey’s Erdogan as Middle East tensions escalate

Blinken meets with Turkey’s Erdogan as Middle East tensions escalate

  • Trending
  • Comments
  • Latest
Top 10 Potash Countries by Production (Updated 2024)

Top 10 Potash Countries by Production (Updated 2024)

August 21, 2024
Top 10 Phosphate Countries by Production (Updated 2024)

Top 10 Phosphate Countries by Production (Updated 2024)

August 1, 2024
Top 10 Uranium-producing Countries (Updated 2024)

Top 10 Uranium-producing Countries (Updated 2024)

November 6, 2024
7 Biggest Lithium-mining Companies in 2024

7 Biggest Lithium-mining Companies in 2024

September 18, 2024
West High YieldResources Ltd. Welcomes Final EAO Decision on Record Ridge Magnesium Project

West High YieldResources Ltd. Welcomes Final EAO Decision on Record Ridge Magnesium Project

0
New Hampshire Gov. Sununu signs $15.2B ‘miracle’ budget into law

New Hampshire Gov. Sununu signs $15.2B ‘miracle’ budget into law

0

Pennsylvania House clears tax credits for new teachers, nurses, police officers

0
Evers signs bipartisan sales tax bill aimed at sparing Milwaukee from bankruptcy

Evers signs bipartisan sales tax bill aimed at sparing Milwaukee from bankruptcy

0
West High YieldResources Ltd. Welcomes Final EAO Decision on Record Ridge Magnesium Project

West High YieldResources Ltd. Welcomes Final EAO Decision on Record Ridge Magnesium Project

August 21, 2025
Morocco, Emmerson Advance Toward US$2.2 Billion Arbitration Over Halted Potash Project

Morocco, Emmerson Advance Toward US$2.2 Billion Arbitration Over Halted Potash Project

August 21, 2025
Pinnacle Silver and Gold

Pinnacle Silver and Gold

August 21, 2025
Osisko Metals Announces Uplisting to Toronto Stock Exchange

Osisko Metals Announces Uplisting to Toronto Stock Exchange

August 21, 2025
Enter Your Information Below To Receive Trading Ideas and Latest News

Error: Contact form not found.

Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!

Recent News

West High YieldResources Ltd. Welcomes Final EAO Decision on Record Ridge Magnesium Project

West High YieldResources Ltd. Welcomes Final EAO Decision on Record Ridge Magnesium Project

August 21, 2025
Morocco, Emmerson Advance Toward US$2.2 Billion Arbitration Over Halted Potash Project

Morocco, Emmerson Advance Toward US$2.2 Billion Arbitration Over Halted Potash Project

August 21, 2025
Pinnacle Silver and Gold

Pinnacle Silver and Gold

August 21, 2025
Osisko Metals Announces Uplisting to Toronto Stock Exchange

Osisko Metals Announces Uplisting to Toronto Stock Exchange

August 21, 2025
  • About us
  • Privacy Policy
  • Terms & Conditions
  • About us
  • Privacy Policy
  • Terms & Conditions

Copyright © 2025 revenueagenda.com | All Rights Reserved

No Result
View All Result
  • Investing
  • Latest News
  • Editor’s Pick
  • Economy

Copyright © 2025 revenueagenda.com | All Rights Reserved