Microsoft has again disabled the ms-appinstaller protocol handler by default due to its abuse by cybercriminals to spread malware. Financially motivated hacking groups and cybercriminals have used it as an entry point for ransomware activity since mid-November 2023. The changes are applicable to App Installer version 1.21.3421.0 or higher. The attacks often involve distributing malicious MSIX app packages via Microsoft Teams or through misleading adverts for legitimate software on search engines.

Cyber attack causes data exposure, loss of emergency warnings in Jackson County – KFVS12
Cyber attack causes data exposure, loss of emergency warnings in Jackson County KFVS12

