A malicious spam campaign delivered BazarLoader by abusing the Windows 10 App Installer mechanism through links using the ms-appinstaller URI scheme. The operation used personalized complaint-themed lures and hosted malicious .appinstaller and .appxbundle files on Microsoft cloud storage, presenting victims with a fake Adobe-branded installer signed with a certificate linked to Systems Accounting Limited while falsely displaying Adobe Inc. as the publisher.
After installation, the payload SecurityFix.exe downloaded and executed a DLL via regsvr32.exe, used delayed execution and process spawning to evade detection, and injected into a headless msedge.exe process to start command-and-control traffic. Sophos said the malware matched BazarBackdoor behavior, including HTTPS cookie-based C2, PowerShell and native-command system profiling, and checks of external services to identify the victim network’s public IP address; Microsoft later tracked the App Installer issue as CVE-2021-43890 and fixed it in a subsequent Patch Tuesday release.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft released a fix for CVE-2021-43890 as part of its January 2022 Patch Tuesday updates. The patch addressed the App Installer vulnerability exploited to deliver BazarLoader.
Microsoft assigned CVE-2021-43890 to the Windows App Installer issue abused in the BazarLoader campaign. The vulnerability tracked the abuse of the App Installer mechanism that enabled delivery of the malicious package.
Sophos documented a malicious spam campaign delivering BazarBackdoor/BazarLoader via complaint-themed lures and links using the ms-appinstaller URI scheme. The attack hosted malicious .appinstaller and .appxbundle files on Microsoft cloud storage and used a fake Adobe-branded installer to launch the malware chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.