Microsoft Threat Intelligence warns that financially motivated actors are abusing the ms-appinstaller protocol to distribute malware via signed MSIX packages and malicious landing pages, tying multiple groups like Storm-0569, Storm-1113, Sangria Tempest, and Storm-1674 to this activity. Microsoft disabled the ms-appinstaller handler by default and outlines mitigations spanning phishing-resistant authentication, user education, Defender/Office protections, and safer browsing practices. #Storm-1674 #BATLOADER
Keypoints
- Multiple financially motivated actors (Storm-0569, Storm-1113, Sangria Tempest, Storm-1674) used App Installer (ms-appinstaller) as an entry vector for malware and ransomware.
- Storm-0569 exploited SEO poisoning and malvertising to push malicious MSIX installers posing as Zoom, Tableau, TeamViewer, and AnyDesk.
- Storm-0569 dropped BATLOADER via PowerShell/batch scripts, delivering payloads like Cobalt Strike Beacons and facilitating data exfiltration and ransomware handoffs.
- Storm-1113 distributed EugenLoader through MSIX installers after spoofed landing pages, delivering Gozi, Redline, IcedID, Smoke Loader, NetSupport, and related tools.
- Sangria Tempest used EugenLoader and subsequently dropped Carbanak/Gracewire, with POWERTRASH (highly obfuscated PowerShell) and Google ads aiding MSIX delivery.
- Storm-1674 leveraged Teams to deliver fake landing pages, spoofing Microsoft services and using Teams messages to propagate malicious installers.
- Mitigations highlighted include phishing-resistant auth, Conditional Access, Safe Links, Defender for Office 365/Defender XDR, PUA protection, and attack surface reduction rules.
MITRE Techniques
- [T1566.001] Phishing: Spearphishing Link – Landing pages spoof legitimate software providers and include links to malicious installers via the ms-appinstaller protocol. ‘…landing pages spoofing the original software provider’s landing pages that include links to malicious installers…’
- [T1566.003] Phishing: Spearphishing via Service – Attacks using Teams to deliver malicious content and landing pages; ‘Tenants created by the threat actor are used to create meetings and send chat messages to potential victims using the meeting’s chat functionality.’
- [T1218] Signed Binary Proxy Execution – Use of malicious MSI installers signed to appear legitimate. ‘maliciously signed Microsoft Installer (MSI) files posing as legitimate software installations…’
- [T1059.001] PowerShell – Storm-0569 uses PowerShell to download BATLOADER. ‘Storm-0569 then uses PowerShell and batch scripts that lead to the download of BATLOADER.’
- [T1059.003] Windows Command Shell – Storm-0569 employs batch scripts to reach BATLOADER. ‘PowerShell and batch scripts that lead to the download of BATLOADER.’
- [T1027] Obfuscated/Compressed Files and Information – POWERTRASH described as ‘highly obfuscated PowerShell script.’
- [T1567.002] Exfiltration to Cloud Storage – Data exfiltration via Rclone tools. ‘data exfiltration using the Rclone data exfiltration tools.’
Indicators of Compromise
- [SHA-256] Storm-0569 indicators – 48aa2393ef590bab4ff2fd1e7d95af36e5b6911348d7674347626c9aaafa255e, 11b71429869f29122236a44a292fde3f0269cde8eb76a52c89139f79f4b97e63, 7e646dfe7b7f330cb21db07b94f611eb39f604fab36e347fb884f797ba462402, ffb45dc14ea908b21e01e87ec18725dff560c093884005c2b71277e2de354866, b79633917e51da2a4401473d08719f493d61fd64a1b10fe482c12d984d791ccb
- [URL] hxxps://scheta[.]site/api.store/ZoomInstaller.msix, hxxps://scheta[.]site/api.store/Setup.msix
- [Domain] teannviewer.ithr[.]org, tab1eu.ithr[.]org, amydeks.ithr[.]org, zoonn.ithr[.]org, scheta[.]site, tnetworkslicense[.]ru, 1204knos[.]ru, 1204networks[.]ru, abobe.ithr[.]org
- [C2] Storm-0506 Cobalt Strike beacon C2 – gertefin[.]com, septcntr[.]com
- [SHA-256] Storm-1113 indicators related to App Installer abuse – 44cac5bf0bab56b0840bd1c7b95f9c7f5078ff417705eeaaf5ea5a2167a81dd5
- [Domain] info-zoomapp[.]com, zoonn[.]meetlng[.]group
- [Domain] storageplace[.]pro, sun1[.]space
- [SHA-256] Sangria Tempest indicators related to App Installer abuse – 2ba527fb8e31cb209df8d1890a63cda9cd4433aa0b841ed8b86fa801aff4ccbd, 06b4aebbc3cd62e0aadd1852102645f9a00cc7eea492c0939675efba7566a6de
- [SHA-256] Storm-1674 indicators related to App Installer abuse – 2ed5660c7b768b4c2a7899d00773af60cd4396f24a2f7d643ccc1bf74a403970
- [Domain] nixonpeabody[.]tech-department[.]us, amgreetings[.]tech-department[.]us, cbre[.]tech-department[.]us, tech-department[.]us, kellyservices-hr[.]com, hubergroup[.]tech-department[.]us, formeld[.]tech-department[.]us, kellyhrservices-my[.]sharepoint[.]com, kellyserviceshr-my[.]sharepoint[.]com