Payouts King Initial Access Broker Deploys Edgecution Malware Through Malicious Edge Extension
ID: e19c742e-d96b-537a-a5e7-091638d6dfb7
STIX ID: report--e19c742e-d96b-537a-a5e7-091638d6dfb7
Feed Name: GBHackers
A coordinated initial-access campaign tied to the Payouts King ransomware ecosystem uses a malicious Edge extension called "Edgecution" plus Chrome native messaging to reach a Python backdoor and achieve persistent host-level control. The attack begins with targeted Microsoft Teams-based social engineering to a fake “Outlook Updates Management Console,” and deploys multiple installation vectors (AutoHotkey, signed AHK executable, encrypted ZIPs, PowerShell/batch scripts) that schedule headless Edge instances loading the sideloaded extension. The extension beacons to cloudfront-hosted WebSocket C2s, forwards privileged commands to the native Python host (via a native_host wrapper and JSON-over-stdio protocol), and supports actions like file writes, process execution, and arbitrary Python execution; the report also includes several C2 URLs and SHA256 hashes as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
