{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/windows-installer/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["living-off-the-land","command-and-control","windows-installer","msiexec"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Windows Installer binary, msiexec.exe, provides functionality to install software from local or network-accessible packages. Adversaries often abuse this legitimate utility by providing a remote URL as a parameter, forcing the process to fetch a malicious Microsoft Installer (MSI) package from an attacker-controlled web server. This technique allows for fileless delivery of second-stage payloads, such as the LokiBot infostealer, by executing code directly within the memory context of the installer process. Defenders should monitor for command-line arguments that include HTTP or HTTPS prefixes combined with calls to msiexec.exe, as this is rarely required for standard administrative software deployment in secure environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker stages a malicious MSI file on an external web server\u003c/li\u003e\n\u003cli\u003eVictim receives a lure (e.g., email attachment or browser-based download) that executes a dropper script\u003c/li\u003e\n\u003cli\u003eDropper script invokes 'msiexec.exe' via the command line\u003c/li\u003e\n\u003cli\u003eThe command line includes a remote URL string pointing to the hosted MSI package\u003c/li\u003e\n\u003cli\u003eMsiExec establishes an outbound network connection to the attacker-controlled host\u003c/li\u003e\n\u003cli\u003eMsiExec downloads the malicious MSI package into a temporary directory\u003c/li\u003e\n\u003cli\u003eWindows Installer service executes the package, which may contain embedded scripts or binaries\u003c/li\u003e\n\u003cli\u003eFinal objective (e.g., malware persistence or information theft) is achieved\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the execution of arbitrary code with the privileges of the invoking user. This has been documented in malware campaigns such as the delivery of LokiBot, which leads to the theft of credentials, exfiltration of sensitive data, and potential lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to monitor for suspicious process executions involving remote URL parameters in the command line. Validate the rule against administrative automation scripts to prevent false positives and tune by allowlisting legitimate internal software distribution servers.\u003c/p\u003e\n\u003ch2 id=\"tags\"\u003eTags\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eliving-off-the-land\u003c/li\u003e\n\u003cli\u003ecommand-and-control\u003c/li\u003e\n\u003cli\u003ewindows-installer\u003c/li\u003e\n\u003cli\u003emsiexec\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T12:20:25Z","date_published":"2026-09-01T12:20:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-msiexec-web-install/","summary":"Adversaries leverage the Windows Installer service (msiexec.exe) to download and execute malicious MSI packages directly from remote web URLs to facilitate stage-two payload delivery.","title":"Detection of MsiExec Web-based Remote Installations","url":"https://feed.craftedsignal.io/briefs/2026-09-msiexec-web-install/"}],"language":"en","title":"CraftedSignal Threat Feed - Windows-Installer","version":"https://jsonfeed.org/version/1.1"}