Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

An initial access broker linked to the Payouts Kings ransomware group has deployed a malicious Microsoft Edge extension, named ‘Edgecution,’ that abuses a legitimate browser-to-host communication API to escape the browser sandbox and install a persistent backdoor on Windows systems. The attack begins with social engineering via Microsoft Teams, where attackers impersonate IT support to convince employees to install the extension. Organizations using Microsoft Edge with extensions enabled, Microsoft Teams, and Microsoft 365 environments face direct risk of ransomware staging and lateral movement with potential for full network compromise.

Author

Tech Jacks Solutions