Payouts King Ransomware Uses Edgecution Malware via Malicious Edge Extension

Payouts King Ransomware Uses Edgecution Malware via Malicious Edge Extension

7h ago ZscalerGbhackers 87% similarity 69.5
Share:

Article Content

Browse articles
ThreatCluster

An initial access broker linked to the Payouts King ransomware has deployed a new malware known as Edgecution. This attack utilizes a malicious Microsoft Edge browser extension that exploits the Chrome native messaging protocol, allowing the malware to interact with host applications beyond the browser's sandbox. The attack begins with social engineering tactics, often impersonating IT staff through Microsoft Teams messages, leading victims to a fake Microsoft website. Victims are prompted to download various scripts that facilitate the installation of the Edgecution malware. The malware enables attackers to manipulate the local filesystem and execute arbitrary code on compromised systems. The campaign represents a significant evolution in ransomware delivery methods, posing a serious risk to organizations using Microsoft Edge. Security professionals are urged to remain vigilant against such social engineering tactics and browser-based malware.

Key Points: • Edgecution malware exploits a malicious Microsoft Edge extension to gain host access. • Attackers use social engineering tactics, impersonating IT staff to deceive victims. • The campaign demonstrates a novel method for ransomware delivery, increasing risk for organizations.

ThreatCluster AI

Timeline

2026-06-23
Zscaler reports on Edgecution malware deployment
Zscaler ThreatLabz reveals details on the Edgecution malware and its delivery method via a malicious Edge extension.
Zscaler
2026-06-24
Gbhackers covers Edgecution malware campaign
Gbhackers publishes an article detailing the Edgecution malware and its connection to the Payouts King ransomware ecosystem.
Gbhackers

Community

Browse all →