Sideloading: A New Malware Delivery Method via Spam Email

Date:

Share post:

Cybercriminals often rely on different malware campaigns to exploit new vulnerabilities and break into critical network systems. The latest security research from the Mimecast threat center uncovered a new malware campaign via Sideloading technique. The threat actor behind this campaign is known for delivering Trickbot and BazarLoader malware payloads on the compromised system that leads to ransomware attacks.

What is Sideloading?

Sideloading is the process of adding an application that is not vetted by the developer of the mobile’s operating system. Threat actors leverage Sideloading technique to spread malware via fake or malicious apps across end-users.  Sideloading method enables access to mobile applications that are unavailable in official app stores.

Exploiting Microsoft Feature

The researchers stated that the attackers behind the campaign had exploited a feature in Microsoft’s App Installer. The App Installer is a software component of Windows 10 used for the installation and maintenance of applications. It allows the users to sideload Windows 10 apps from a web page while bypassing the Windows store.

“Unfortunately, a threat actor known for spreading Trickbot and BazarLoader, which deliver spam often resulting in ransomware attacks, has exploited this feature. This is yet another example of the importance of updated email antispam software to help prevent ransomware attacks,” the researchers said.

The researchers found that scammers sent legitimate-looking emails with malicious attachments to unwitting users, tricking them to click or download. The attackers created a sense of urgency by keeping the email subject as a customer complaint. Instead of downloading, the users are tricked into thinking they need an app to view the email attachment. But when users click install, they end up downloading an app bundle used by Windows 10 containing malware.

The researchers claim that this campaign has been seen more than 16,000 times across varying countries, including the U.S., the U.K., Germany, Australia, and South Africa.

Conclusion

This campaign represents the importance of implementing robust email security software by organizations to prevent malware threats. Companies can initiate an effective email antispam security and train their employees on phishing threats, eventually strengthening the overall security posture.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...

From Awareness to Relevance: Rethinking How We Teach Cybersecurity

Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their...

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...