news.mlab.sh
Back to the feed
malware

Malicious Edge extension abuses Native Messaging as bridge to malware

High
Summary

A malicious Microsoft Edge extension, ‘Edgecution,’ was used in a ransomware attack by exploiting Native Messaging to bypass browser security sandboxes and deploy a Python-based backdoor. The attack, linked to the Payouts Kings ransomware operation via an initial access broker, involved tricking users into installing a fraudulent update, ultimately allowing the malware to execute commands and gain persistent access to compromised systems. This highlights the evolving sophistication of ransomware tactics and the importance of robust extension monitoring.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.