Tag
medium
advisory
Abuse of AppX Deployment Service for Malicious Package Installation
1 ruleAdversaries are leveraging the Windows AppX deployment mechanism to execute malicious packages by placing them in non-standard file paths to bypass traditional deployment directory restrictions.
windows
appx
stealth
persistence
1r
high
advisory
Remote AppX Package Downloaded from File Sharing or CDN Domain
1 rule 3 TTPs 35 IOCsThis brief details the detection of a malicious AppX package downloaded from untrusted file-sharing or CDN domains, a technique employed by threat actors like BazarLoader to deliver malware via abused Windows app mechanisms, potentially leading to system compromise and ransomware.
Windows AppX
appx
malware
initial-access
stealth
windows
1r
3t
35i