March 11, 2024, 12:21 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

An MSIX malware disguised as the Notion installer is being distributed. The distribution website looks similar to that of the actual Notion homepage.


Figure 1. Website that distributes malware


 


The user gets a file named ‘Notion-x86.msix’ upon clicking the download button. This file is Windows app installer, and it is signed with a valid certificate.


Figure 2. The signature information of the malicious installer


 


The user gets the following pop-up upon running the file. Upon clicking the Install button, Notion …

app app installer button clicking disguised distributed distribution download file installer malware malware analysis msix notion website windows x86

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior Security Researcher, SIEM

@ Huntress | Remote Canada

Senior Application Security Engineer

@ Revinate | San Francisco Bay Area

Cyber Security Manager

@ American Express Global Business Travel | United States - New York - Virtual Location

Incident Responder Intern

@ Bentley Systems | Remote, PA, US

SC2024-003533 Senior Online Vulnerability Assessment Analyst (CTS) - THU 9 May

@ EMW, Inc. | Mons, Wallonia, Belgium