Windows Sandbox, which is a lightweight virtual desktop, can now have Microsoft Store installed in it using a simple PowerShell script.
The group is abusing trusted remote management and file transfer tools to deliver a Linux encryptor on Windows machines.