March 11, 2024, 12:21 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

An MSIX malware disguised as the Notion installer is being distributed. The distribution website looks similar to that of the actual Notion homepage.


Figure 1. Website that distributes malware


 


The user gets a file named ‘Notion-x86.msix’ upon clicking the download button. This file is Windows app installer, and it is signed with a valid certificate.


Figure 2. The signature information of the malicious installer


 


The user gets the following pop-up upon running the file. Upon clicking the Install button, Notion …

app app installer button clicking disguised distributed distribution download file installer malware malware analysis msix notion website windows x86

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC