logo

Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs

ID: fb18ec01-e587-5b3f-9a8c-eecbbcc379f5

STIX ID: report--fb18ec01-e587-5b3f-9a8c-eecbbcc379f5

Feed Name: KnowBe4 Blog

Threat Score
75/100

Date Published: 2026-07-10

Date Updated: 2026-07-23

Author: KnowBe4 Team

...
...

Zscaler researchers report that an initial access broker associated with the Payouts King ransomware gang is using Microsoft Teams phishing to trick victims into installing a malicious Microsoft Edge extension. The extension abuses the Chrome native messaging protocol to escalate beyond the browser sandbox, allowing attackers to manipulate files, launch processes, and execute arbitrary code; the broker then sells the foothold to the ransomware group. Organizations are advised to monitor browser extension installations, control native messaging hosts, and train users to recognize spoofed IT prompts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.