Close Menu
Read Us 24×7
    What's Hot
    Sukanya Samriddhi Yojana

    Benefits of Sukanya Samriddhi Yojana for Savings

    May 13, 2025
    Best Automated Penetration Testing Tools

    10 Best Automated Penetration Testing Tools

    May 13, 2025
    Backlit Keyboards

    7 Best Backlit Keyboards for Every Budget

    May 12, 2025
    Facebook X (Twitter) Instagram Pinterest LinkedIn
    Trending
    • Benefits of Sukanya Samriddhi Yojana for Savings
    • 10 Best Automated Penetration Testing Tools
    • 7 Best Backlit Keyboards for Every Budget
    • Top 11 “Best Buy” Alternatives for Your Electronics Needs in 2025
    • Dark Oxygen: Redefining Our Understanding of Oxygen Production in the Deep Ocean
    • YouTube Audio Downloader: Your Music Liberation Tool 🎵
    • A Deeper Look at What It Is Like Working at a Prop Firm
    • 17 Best Android App Development Software of 2025
    Facebook X (Twitter) Instagram Pinterest LinkedIn
    Read Us 24×7
    • Home
    • Technology
      Best Automated Penetration Testing Tools

      10 Best Automated Penetration Testing Tools

      May 13, 2025
      Backlit Keyboards

      7 Best Backlit Keyboards for Every Budget

      May 12, 2025
      Dark Oxygen

      Dark Oxygen: Redefining Our Understanding of Oxygen Production in the Deep Ocean

      May 9, 2025
      Android App Development Software

      17 Best Android App Development Software of 2025

      April 24, 2025
      Why Choose an AI Learning Tablet TalPad T100 Explained

      Why Choose an AI Learning Tablet TalPad T100 Explained

      April 16, 2025
    • Business
      Sukanya Samriddhi Yojana

      Benefits of Sukanya Samriddhi Yojana for Savings

      May 13, 2025

      A Deeper Look at What It Is Like Working at a Prop Firm

      May 1, 2025
      FintechZoom.IO

      FintechZoom.IO: Revolutionizing Fintech in 2025

      April 7, 2025
      Crypto Management

      Unhosted: Revolutionizing Crypto Management with Advanced Wallet Technology

      March 20, 2025
      Bank of America Hit With Lawsuit From UBS

      Bank of America Hit With Lawsuit From UBS: What You Need to Know

      January 14, 2025
    • Entertainment
      YouTube Audio Downloader

      YouTube Audio Downloader: Your Music Liberation Tool 🎵

      May 9, 2025
      Firestick

      10 Amazing Benefits of Owning a Firestick You Need to Know

      April 24, 2025
      nhentainet

      nhentai.net – Why It’s Attracting Global Attention?

      April 20, 2025
      chatgpts-ghibli-art-generator-goes-viral-why-is-everyone-obsessed

      ChatGPT’s Ghibli Art Generator Goes Viral – Why is Everyone Obsessed?

      March 29, 2025
      Taylor Swift's Producer Suggests New Album on the Horizon

      Taylor Swift’s Producer Suggests New Album on the Horizon

      March 28, 2025
    • Lifestyle
    • Travel
    • Tech Q&A
    Read Us 24×7
    Home » Microsoft Disables MSIX Protocol Handler in Response to Malware Attacks
    Technology

    Microsoft Disables MSIX Protocol Handler in Response to Malware Attacks

    Sayan DuttaBy Sayan DuttaDecember 29, 20233 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Reddit Email WhatsApp
    Microsoft Disables MSIX Protocol Handler in Response to Malware Attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email Reddit WhatsApp

    Microsoft has recently disabled the MSIX handler in Windows 10 and 11, which was used by malicious actors to distribute malware through the App Installer feature. This article will explain how the MSIX handler was abused, what kind of malware attacks were carried out, and what mitigations Microsoft has implemented to protect users.

    Microsoft Addresses App Installer Abuse

    The App Installer feature in Windows allows users to install applications from various sources, such as the Microsoft Store, local files, or web URLs. One of the supported formats for app packages is MSIX, which is a modern and secure packaging format that supports both desktop and UWP apps.

    However, the App Installer feature also had a spoofing vulnerability that could allow attackers to trick users into installing malicious apps. The vulnerability was related to the code signing certificates that are used to verify the authenticity and integrity of the app packages. The App Installer feature did not properly validate the certificates and could display a fake or tampered certificate to the user, making it appear as if the app was from a trusted source.

    This vulnerability was exploited by malware groups such as BazarLoader, which used phishing emails and fake websites to lure users into downloading and installing malicious MSIX packages. The malware could then perform various malicious activities, such as stealing credentials, encrypting files, or delivering ransomware.

    Malware Attacks Using MSIX Protocol Handler

    One of the ways that the attackers exploited the App Installer feature was by using the MSIX ms-appinstaller protocol. This is a custom URI scheme that can be used to launch the App Installer feature and install an app from a web URL. For example, a link like ms-appinstaller:?source=https://example.com/app.msix would open the App Installer feature and prompt the user to install the app from the specified URL.

    The attackers used this protocol to distribute the BazarLoader malware, which is a sophisticated backdoor that can download and execute additional payloads. The attackers created phishing emails and fake websites that contained links to the ms-appinstaller protocol and tried to trick users into clicking on them. The links would point to malicious packages hosted on Microsoft Azure, which is a cloud computing platform that offers various services, including web hosting. The attackers used Azure to host their malware because it could bypass some security filters and make the links look more legitimate.

    Mitigations Implemented by Microsoft

    In response to the malware attacks, Microsoft has taken several steps to mitigate the threat and protect users from installing malicious software. One of the main actions that Microsoft has taken is to disable the ms-appinstaller URI scheme handler in Windows 10 and 11. This means that the links that use the ms-app installer protocol will no longer work, and users will not be able to install apps from web URLs using the App Installer feature. Microsoft has also removed the option to install apps from web URLs from the App Installer user interface.Additionally, Microsoft has also improved the validation of code signing certificates in the App Installer feature and has added more warnings and prompts to inform users of the potential risks of installing apps from unknown sources. Microsoft has also advised users to only install apps from trusted sources, such as the Microsoft Store, and to use antivirus software and other security tools to detect and remove any malware infections.

    Share. Facebook Twitter Pinterest LinkedIn Email Reddit WhatsApp
    Previous ArticleMcAfee Warns of Xamalicious: Android Users, Remove These 13 Apps Now
    Next Article Is Former Miss Bolivia Arrested? Why Was She Arrested? 
    Avatar for Sayan Dutta
    Sayan Dutta
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • LinkedIn

    I am glad you came over here. So, you want to know a little bit about me. I am a passionate digital marketer, blogger, and engineer. I have knowledge & experience in search engine optimization, digital analytics, google algorithms, and many other things.

    Related Posts

    Best Automated Penetration Testing Tools
    Technology

    10 Best Automated Penetration Testing Tools

    May 13, 2025
    Backlit Keyboards
    Technology

    7 Best Backlit Keyboards for Every Budget

    May 12, 2025
    Dark Oxygen
    Technology

    Dark Oxygen: Redefining Our Understanding of Oxygen Production in the Deep Ocean

    May 9, 2025

    Table of Contents

    • Microsoft Addresses App Installer Abuse
    • Malware Attacks Using MSIX Protocol Handler
    • Mitigations Implemented by Microsoft

    Top Posts

    Sukanya Samriddhi Yojana

    Benefits of Sukanya Samriddhi Yojana for Savings

    May 13, 2025
    Best Automated Penetration Testing Tools

    10 Best Automated Penetration Testing Tools

    May 13, 2025
    Backlit Keyboards

    7 Best Backlit Keyboards for Every Budget

    May 12, 2025
    Best Buy Alternatives

    Top 11 “Best Buy” Alternatives for Your Electronics Needs in 2025

    May 11, 2025
    Popular in Social Media
    Anon IG Viewer

    Anon IG Viewer: Best Anonymous Viewer for Instagram

    April 3, 2025
    CFBR

    How to Use CFBR Appropriately? (Pros and Cons)

    September 24, 2024
    EU to Get WhatsApp, Messenger Interoperability with iMessage, Telegram and More

    EU to Get WhatsApp, Messenger Interoperability with iMessage, Telegram and More

    September 9, 2024
    New in Health
    9 Reasons Why People in Their 40s Should Take Daily Supplements

    9 Reasons Why People in Their 40s Should Take Daily Supplements

    April 8, 2025
    Why Put Your Tampons In The Freezer

    Why Put Your Tampons In The Freezer? (Answered)

    November 26, 2024
    WellHealthOrganic Buffalo Milk Tag

    WellHealthOrganic Buffalo Milk Tag: Unveiling Nutritional Brilliance

    November 13, 2024

    google news

    google-play-badge

    Protected by Copyscape

    DMCA.com Protection Status

    Facebook X (Twitter) Instagram Pinterest
    • Terms of Service
    • Privacy Policy
    • Contact Us
    • About
    • Sitemap
    • Write For Us
    • Submit Press Release
    Copyright © 2025 - Read Us 24x7

    Type above and press Enter to search. Press Esc to cancel.