Edge users beware — this malicious extension can break out of the sandbox and install ransomware | #ransomware | #cybercrime



  • Zscaler uncovered “Edgecution,” a malicious Edge extension deployed via fake Outlook update sites shared in Teams phishing
  • Attack uses ZIP archives with Python runtime to escape browser sandbox, creating a backdoor capable of shell/PowerShell execution and system data theft
  • Believed linked to Initial Access Brokers tied to ransomware group Payout Kings, showing evolving sophistication in access‑for‑sale operations

If you are using the Edge browser be careful – there is a malicious campaign going round that uses the browser to deploy a backdoor via an extension.

According to security researchers Zscaler, scammers are reaching out to their victims via Microsoft Teams, pretending to be IT support. They claim the user needs to install an Outlook update, or a spam filter, and direct the victims to a fake “Outlook Updates Management Console” website.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW