malware
Malicious Edge extension abuses Native Messaging as bridge to malware
High
Summary
A malicious Microsoft Edge extension, ‘Edgecution,’ was used in a ransomware attack by exploiting Native Messaging to bypass browser security sandboxes and deploy a Python-based backdoor. The attack, linked to the Payouts Kings ransomware operation via an initial access broker, involved tricking users into installing a fraudulent update, ultimately allowing the malware to execute commands and gain persistent access to compromised systems. This highlights the evolving sophistication of ransomware tactics and the importance of robust extension monitoring.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data