Microsoft has disabled the App Installer feature of Windows 10, which allowed direct installation of apps from web links. The move comes after a surge in abuse by threat actors using the feature to deploy ransomware and other malware. The MS-appinstaller protocol could bypass Microsoft Defender SmartScreen and built-in browser warnings for malicious downloads, and became a preferred method for these actors. This protocol was disabled on December 28, 2021.

Malware spread taking place with exploitation of Claude Code – Cybersecurity Insiders
Malware spread taking place with exploitation of Claude Code Cybersecurity Insiders

