216.73.216.36

Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware

· Published 23/06/2026 18:41

Export JSON

Essential information

Published
23/06/2026 18:41
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
browser extension edgecution initial access broker python backdoor social engineering
Related entities
2 indicators, 1 intrusion sets (apt), 21 techniques (mitre), 1 malware

Description

An linked to Payouts King ransomware is deploying Edgecution, a sophisticated malware utilizing a malicious Microsoft Edge . The attack begins through via Microsoft Teams, impersonating IT staff and directing victims to fake Microsoft websites offering supposed Outlook updates. Edgecution comprises two components: a that communicates with command-and-control servers via websockets, and a Python-based backdoor. The extension abuses Chrome native messaging protocol to escape browser sandbox restrictions, enabling direct host access. This allows attackers to manipulate the filesystem, launch processes, and execute arbitrary code. The malware operates in a headless browser, remaining invisible to users. Deployment methods include AutoHotKey scripts, Windows batch scripts, and PowerShell scripts. The supports various commands including system information collection, filesystem access, and arbitrary code execution.

External references