Latest

Related Posts

Microsoft Takes Down Abused App Installer Targeted by Hackers

Microsoft Threat Intelligence has found that App Installer is a way for several players, such as Storm-0569, Storm-1113, Sangria Tempest, and Storm-1674, to spread ransomware that is run by humans.

- Advertisement -

Microsoft Takes Down Abused App Installer: Threat players, especially those who want to make money, have been seen using the ms-app installer URI scheme (App Installer) to spread malware. Microsoft has turned off the ms-appinstaller protocol driver by default because of this.

The Microsoft Threat Intelligence team said, “The observed threat actor activity abuses the current implementation of the ms-app installer protocol handler as a way for malware to get in, which could lead to the distribution of ransomware.”

- Advertisement -

Microsoft Takes Down Abused App Installer Targeted by Hackers

Threat actors likely chose the ms-appinstaller protocol handling vector because it can get around security measures like Microsoft Defender SmartScreen and built-in browser alerts for getting executable file types, which are meant to keep users safe from malware.

Microsoft Threat Intelligence has found that App Installer is a way for several players, such as Storm-0569, Storm-1113, Sangria Tempest, and Storm-1674, to spread ransomware that is run by humans.

People have seen people pretending to be legitimate applications, getting people to install harmful MSIX packages that look like legitimate applications, and avoiding detection on the original installation files.

Microsoft found that Storm-0569 was spreading BATLOADER by pretending to be websites like AnyDesk, Zoom, Tableau, and TeamViewer that gave real files. This was done by using search engine optimization (SEO) poisoning.

When someone searches on Bing or Google for a real piece of software, they might see links to harmful downloads that use the ms-app installer protocol on a landing page that looks like it belongs to the real software provider. Spoofing and copying well-known, real software is a common way to trick people into giving you money.

Catholic Benefits Association: Introducing Religious Investment Guidelines in MEP

Microsoft found out that Storm-1113’s EugenLoader was being spread through search ads that looked like the Zoom app. When a user visits a hacked website, a harmful MSIX installer called EugenLoader is downloaded onto their device. This installer is then used to spread other viruses.

There’s a chance that these packages have malware installs that have been seen before, such as Gozi, IcedID, NetSupport Manager (also known as NetSupport RAT), Lumma stealer, and Sectop RAT.

EugenLoader from Storm-1113 is used by Sangria Tempest. It was spread through rogue MSIX package installs. Another thing Sangria Tempest does is spread Carbanak, a backdoor that the hacker has been using since 2014 and that then spreads the Gracewire malware implant.

Because they want to make money, hackers known as Sangria Tempest (formerly ELBRUS, sometimes tracked as Carbon Spider, FIN7) mostly use ransomware like Clop or demand money from people after breaking into systems and stealing data.

Storm-1674 sent texts with fake web pages through Teams. The home pages look like those of a lot of different companies, as well as Microsoft services like OneDrive and SharePoint. Tenants that the threat actor sets up can set up meetings and talk to possible victims through the meeting’s chat tool.

Recommendation

  • Create and use user login methods that are not vulnerable to hacking.
  • Increase the strength of Conditional Access security so that it requires identification that can’t be stolen by phishing.
  • Teach Microsoft Teams users to check the “External” tag on messages sent by outside organizations.
  • Get people to use Microsoft Edge and other web browsers that work with Microsoft Defender SmartScreen.
  • Make Microsoft Defender for Office 365 check links again every time you click on them.
  • To stop popular attack methods, turn on attack surface reduction rules.
Eric Joseph Gomes
Eric Joseph Gomeshttps://www.eduvast.com/
Seasoned professional blog writer with a passion for delivering high-quality content that informs, educates, and engages readers.

Popular Articles

We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners. View more
Cookies settings
Accept
Privacy & Cookie policy
Privacy & Cookies policy
Cookie name Active
PRIVACY POLICY
  1. General
  • (1.1.) Eduvast (“Eduvast”, “We”, “Our”, “Us”) is committed to the protection of personal information provided by the users (“You”,“Your”,“User”) to Eduvast. You agree that Your use of Eduvast implies Your consent to the collection, retention and use of Your personal information in accordance with the terms of this Privacy Policy (“Privacy Policy”).
  • (1.2.) We take the privacy of our Users seriously. We are committed to safeguarding the privacy of Users while providing personalized and valuable service.
  • (1.3.) While We do Our best to protect Your information, particularly with respect to the protection of Your personal data, Eduvast cannot ensure the security of Your data transmitted via the internet, telephone or any other networks.
  • (1.4.) Access to the contents available  is conditional upon Your acceptance of this Privacy Policy which should be read together with the End User License Agreement“EULA”.
  • (1.5.) If You do not agree to any of the provisions of this Privacy Policy or EULA, You should not download, install and use the App. We may revise, alter, add, amend or modify this Privacy Policy at any time by updating this privacy policy. By downloading, installing and/or using this App, You agree to be bound by any such alteration, amendment, addition or modification.
2. Information Collected Non Personal Information
  • (2.1.) We may collect non-personal information about You whenever You access or interact with Our Website or any of the related services. This includes but not limited to browser name, version, server location, device specific information such as the type of device used, users’ operating system and version, your mobile devices unique device ID, third party apps or App or service that referred users to App, language preference, means of connection to App, internet service providers, IP address, technical information, google advertising ID (GAID), IDFA, GAID Opt-out Status, location information, interaction of Your device with the App and applications, details of Your device including without limitation its manufacturer details, height and width of your device screen, model, version, UDID or IMEI Number and other similar information about You(collectively "Traffic Data”). Personal Information
  • (2.2.) 2.2. We may collect personal information that identifies You in a variety of ways, including, but not limited to the information submitted during download and installation of the App or in connection with registration for other activities or features offered through the App. Personally identifiable information collected may include name, mailing address, email address, phone number and demographic information such as gender, nationality, postcode and other personal information including but not limited to date, time or place of birth ("Personal Information"). If You communicate with Us by, for example, e-mail or letter, any information provided in such communication may be collected by Eduvast.
  • (2.3.) Our website may transmit your Personal Information to our internal servers. This Personal Information is immediately deleted once you delete the App, except to the extent it is necessary to store the same under applicable laws. Further, we have implemented commercially reasonable physical, managerial, operational and technical security measures to protect the loss, misuse and alteration and to preserve the security of the Personal Information in our care.Finally, this information is used strictly in line with our business purposes.
  • (2.4.) You understand that once You leave Our servers, use of any information You provide shall be governed by the privacy policy of the operator of the site used by You.
3. Disclosure of Personal Information
    • (3.1.) We do not disclose Your Personal Information to any third parties other than as may be required by us, Eduvast’s affiliates, partners, trusted business networks, in compliance with our Privacy Policy for the purpose of moderating the content of the Website, enhancing Your user experience, providing You localised content and to enable Us and Our partners to provide You with targeted information which may be of benefit to you.
    • (3.2.) To enhance customer experience and to provide focused support, we may share generic aggregated demographic information which may include Your information collected by Us but not linked to any personally identifiable information regarding visitors and users with Our business partners, trusted affiliates and advertisers for the purposes outlined above.
    • (3.3.) At times We are required by law or litigation to disclose personal information about the users. We may also disclose information about the user if We determine that disclosure of information is necessary for national security, law enforcement, or other issues of public importance.
    • (3.4.) We use Our best efforts to use information in aggregate form (so that no individual User is identified) for the following purposes:
(3.4.1) To build up marketing profiles; (3.4.2) To aid strategic development, data collection and business analytics; (3.4.3) To manage our relationship with advertisers and partners; (3.4.4) 3.4.4. To audit usage of Our website i.e. www.www.eduvast.com (3.4.5) 3.4.5. To enhance user experience in relation to the App and Our website (collectively, “Permitted Use”).
  • (3.5.) We reserve the right to disclose Personal Information if required to do so by law or if we believe that it is necessary to do so to protect and defend the rights, property or personal safety of Eduvast, the App, or Users.
4. Cookies
  • (4.1.) Whenever You access the App We may place "cookies" on Your hard drive for record-keeping purposes to enhance Your experience or sometimes to personalize Your experience. Cookies are small text files that are placed on Your device's hard drive by the App You visit. Cookies help Us to identify information relating Your activities and to retain information relating to Your preferences and history on the App.
  • (4.2.) Ad targeting cookies: We and/or Our service providers may use advertising cookies to deliver ads that are more relevant to You and Your interests.
  • (4.3.) You may choose to disable cookies by turning off cookie feature on the web browser. However, by disabling this feature, some parts of the App may not function properly. This may prevent You from taking full advantage of the App.
5. Confidentiality
    • (5.1.) Except as otherwise provided in this Privacy Policy, We will keep Your Personal Information private and will not share it with third parties, unless We believe in good faith that disclosure of Your Personal Information or any other information We collect about You is necessary for Permitted Use or to:
(5.1.1.) Comply with a court order or other legal process; (5.1.2.) Protect the rights, property or safety of Eduvast or another party; (5.1.3.) Enforce the Agreement, including EULA; or (5.1.4.) Respond to claims that any posting or other content violates the rights of third-parties. 6. Security
  • (6.1.) The security of Your Personal Information is important to Us. We follow generally accepted industry standards to protect the Personal Information submitted to Us, both during transmission and once We receive it.
  • (6.2.) Although We make best possible efforts to store Personal Information in a secure operating environment which is not open to the public, You should understand that there is no such thing as complete security, and We do not guarantee that there will be no unintended disclosures of Your Personal Information. If We become aware that Your Personal Information has been disclosed in a manner not in accordance with this Privacy Policy, We will use reasonable efforts to notify You of the nature and extent of such disclosure (to the extent We know that information) as soon as reasonably possible and as permitted by law.
7. Updates and Changes to Privacy Policy
  • We reserve the right, at any time, to add to, change, update, or modify this Privacy Policy so please review it frequently. In all cases, use of information We collect is subject to the Privacy Policy in effect at the time such information is collected. You hereby acknowledge and agree that it is Your responsibility to review this Privacy Policy periodically and become aware of the modifications. If You disagree to any of the changes to the Privacy Policy, You shall refrain from using or accessing the App. Your continued use of the App following the posting of the revised Policy shall indicate Your acceptance and acknowledgment of the changes and You will be bound by it.
8. Updates and Changes to Your Personal Information
  • You have a right to correct any errors in Your Personal Information available with Us. You may request Us in writing that We cease to use Your Personal Information.
9. Contact Us
  • You may write to us at [email protected] for any privacy concerns and requests relating to this EULA and Privacy Policy.
Save settings
Cookies settings