Microsoft has disabled a significant software tool to prevent malware attacks, while Teams is also being exploited for malware phishing.
The tech giant has disabled the ms-appinstaller protocol handler as the default because it had found evidence that the hackers had been exploiting the software to distribute malware. Microsoft states that these hackers potentially selected the ms-appinstaller protocol handler vector because it could bypass mechanisms built to safeguard users against malware, including Microsoft Defender SmartScreen and native browser warnings for downloads of executable file formats.
In a blog written by Microsoft Threat Intelligence, the company noted:
In addition to ensuring that customers are protected from observed attacker activity, Microsoft investigated the use of App Installer in these attacks. In response to this activity, Microsoft has disabled the ms-appinstaller protocol handler by default. The observed threat actor activity abuses the current implementation of the ms-appinstaller protocol handler as an access vector for malware that may lead to ransomware distribution."
Microsoft also observed hackers selling malware kits on the dark web that utilised the MSIX file format and the ms-appinstaller protocol handler.
Microsoft said that the hackers were designing "malicious" adverts for "legitimate and popular software" to send possible victims towards websites the bad actors control before manipulating them into downloading the malware packages.
Microsoft added that Teams is also being used as another distribution vector for phishing.
Microsoft name-checked four threat actors that have exploited the App Installer program to date — Storm-0569, Storm-1113, Sangria Tempest, and Storm-1674.
Last month, Microsoft observed instances where the latter hacker designed fake landing pages via messages delivered using Teams. The landing pages imitate Microsoft solutions like OneDrive and SharePoint. "Tenants created by the threat actor are leveraged to create meetings and send chat messages to potential victims using the meeting’s chat functionality," Microsoft explained.
A Challenging Year for Microsoft and Malware
Microsoft experienced several significant cybersecurity attacks last year, including notable assaults on one of its classic communications platforms, Skype.
In October, compromised Skype accounts were reportedly being hacked to spread the DarkGate malware, while Microsoft Teams was also targeted.
As first reported by Trend Micro, multiple Skype business accounts were compromised and then utilised as an environment to distribute a VBA loader script attachment. It was uncertain how the Skype accounts became compromised, but Trend Micro suggested that it was “either through leaked credentials available through underground forums or the previous compromise of the parent organisation”.




