Malicious Edge extension "Edgecution" bypasses browser sandbox to install ransomware
Security firm Zscaler has uncovered a malicious Microsoft Edge extension called "Edgecution," spread via fake Outlook update sites linked in Microsoft Teams phishing messages. Once installed, the extension uses ZIP archives with a Python runtime to escape the browser sandbox, creating a backdoor capable of PowerShell and shell command execution. The campaign is linked to Initial Access Brokers tied to the Payout Kings ransomware group.
Zscaler uncovered “Edgecution,” a malicious Edge extension deployed via fake Outlook update sites shared in Teams phishingAttack uses ZIP archives with Python runtime to escape browser sandbox, creating a backdoor capable of shell/PowerShell execution and system data theftBelieved linked to Initial Access Brokers tied to ransomware group Payout Kings, showing evolving sophistication in access‑for‑sale operationsIf you are using the Edge browser be careful - there is a malicious campaign going round that uses the browser to deploy a backdoor via an extension.According to security researchers Zscaler, scammers are reaching out to their victims via Microsoft Teams, pretending to be IT support. They claim the user needs to install an Outlook update, or a spam filter, and direct the victims to a fake “Outlook Updates Management Console” website. There, the users are instructed to run one of the three provided processes, all of which download a ZIP archive that, when executed, creates a scheduled task. This task starts the Edge browser in headless mode (invisible to the user) and installs an extension officially called “Edge Monitoring Agent”. Zscaler, on the other hand, calls it “Edgecution”.Creating a Native Messaging manifestThe ZIP archive also contains an embedded Python runtime and a Python-based backdoor. The runtime creates a Native Messaging manifest - a file that tells the browser how to communicate with the backdoor. That’s the way the threat actors managed to escape the browser’s sandbox and run the backdoor on the compromised computer itself. That backdoor can do multiple things, from executing shell commands, to running PowerShell and arbitrary Python code. It can also write files on the host, enumerate running processes, and gather system information. Zscaler believes this is the work of an Initial Access Broker (IAB), a malicious group whose only job is to obtain access to a victim’s infrastructure and then sell it - or share it with a partnering group. This particular IAB, the researchers believe, is connected to a ransomware operation called Payout Kings. “The Edgecution browser extension illustrates the evolving sophistication of initial access brokers operating in the ransomware landscape,” Zscaler warns. “The reliance on a malicious browser extension to relay commands to a Python-based native host demonstrates a creative approach to evade traditional endpoint detection.”A full list of Indicators of Compromise (IoC) can be found on this link.Via BleepingComputer
Former two-division UFC champion Conor McGregor has publicly admitted that his rise to stardom caused him to "get lost," acknowledging the "pitfalls" that came with worldwide fame. The Irish fighter spoke candidly about the personal toll of his celebrity status.
Halo Studios' executive producer Damian Kahn and creative director Max Schlomberg have confirmed that the three new missions in Halo Campaign Evolved were created with input from Halo book author Troy Denning. The missions, part of Operation: METEORITE, explore the relationship between Sergeant Johnson and Master Chief. The studio recommends players complete the original campaign before tackling the new content.
Halo Campaign Evolved's executive producer, Damian Kahn, says the team wanted to explore the relationship between Sergeant Johnson and Master Chief for the three new missionsThe new missions were also inspired by Troy Denning's Halo novelsHalo Studios suggests players play them after the original storyHalo Campaign Evolved executive producer Damian Kahn and creative director Max Schlomberg have confirmed that the remake's three new missions were created with the help of Halo book author Troy Denning.In an interview with TechRadar Gaming at Summer Game Fest 2026, where we went hands-on with the upcoming game, the developers explained that the Halo universe has a lot to explore, but they wanted to explore the relationship between Sergeant Johnson and Master Chief in the missions of Operation: METEORITE."If you think about it, in the original game, you see Sergeant Johnson as such an important character in these original games, but you don't really get to know Sergeant Johnson that well, or his relationship with Chief," Kahn said. "That really set the stage for us creatively to think about, 'Hey, let's talk about a mission that they went on a year before the events of The Ring,' and then really to go into their relationship and how they fight alongside each other."Even beyond that, there's all this other universe. You've got Spartans and ODSTs. You've got the Brutes. You've got the Prophets. It's really just us leaning into these other elements of the story that we can tell more deeply, that then let you go back and appreciate more of the campaign and what's there."Schlomberg added that Troy Denning, one of the authors who writes some of the Halo novels, like Halo: Last Light, Halo: Retribution, and Halo: Silent Storm - A Master Chief Story, also "helped with the story" of the three missions."It's a lore-authentic story," he said, explaining that series veterans who have been fans for 25 years and played on Xbox or PC are going to get new bits of information that they've been wanting, allowing them to "piece more of the puzzle together," such as the Covenant War."It's really going to be fun for them," Schlomberg added. "But then also, if you're brand new to the experience, maybe you're a PlayStation player, you've never played before, and this is going to be something that would be really good to play after you play the main ring storyline."However, the creative director suggests that players play the new missions "after they've played and experienced the original.""It is meant to be played that way, because we've made it more of an intermediate difficulty experience, it's a little bit progressed further along. You start off, and it's a little bit more challenging than the first mission of Halo," he said."But again, you can play it in any order you would like. We're not going to make you choose or anything like that, but we just suggest that you play it that way."Halo Campaign Evolved arrives on July 28 for PS5, Xbox Series X and Series S, and PC.
A heatwave sweeping Germany has prompted a series of restrictions across multiple cities. Cottbus and Erfurt have banned the lighting of candles at cemeteries due to fire risk, several football associations have cancelled weekend matches, and Potsdam has shortened its municipal office opening hours. Local authorities are urging residents to take precautions.
A giant corpse flower (Amorphophallus titanum) has bloomed at the Botanical Garden of the University of Wrocław — one of the world's largest and rarest-blooming plants, notorious for its intensely unpleasant smell. A live stream of this rare event is available online for those who want to witness it without the odour.
HBO Max has announced an eight-part documentary series titled "JAY-Z In 8," spanning the full career of the rapper. The series is directed by legendary music producer Rick Rubin. No exact premiere date has been given yet, with the series set to launch later this year.
Doctors are stunned by reports that a CT scan may have been performed on a deceased patient at Warsaw's Southern Hospital. "We have never encountered anything like this," they told Interia. Two shocking threads have emerged in the scandal surrounding the facility, with physicians explicitly calling one of them a breach of the law.
The loganberry is a large, sweet fruit resembling a strawberry growing on thorny canes, still relatively unknown in Poland despite being easy to cultivate in home gardens. The author recalls eating it as a child from her grandfather's allotment without knowing its name. The plant thrives without much effort and is described as a delicious, underrated garden fruit worth growing.
Investors have pulled $651 million from bitcoin ETFs so far this week, according to data from SoSoValue, marking a record outflow. The mass exodus coincides with bitcoin hitting its lowest price level since 2024, signalling growing caution among crypto investors.
Iran appears to be asserting greater control over the Strait of Hormuz, a critical oil transit route connecting the Persian Gulf to the open ocean. The move has pushed oil prices higher and raised fears of fresh supply shocks on global energy markets.
The two men accused of stealing equipment belonging to the England national football team at the 2026 World Cup are Afghan nationals who received US citizenship for collaborating with American forces against the Taliban. Both men have pleaded not guilty. The case has attracted significant international media attention.
Fox News anchor Sean Hannity has addressed public concern after viewers noticed a visible change in his appearance. He spoke about his raspy voice and puffy face, which prompted worried comments from his audience. However, he did not provide a detailed medical explanation for the changes.
Players and retailers are expressing anger over five controversial decisions made by Rockstar Games regarding GTA 6. Both individual gamers and the retail sector have been affected by the choices, which are described as scandalous. The source lists the grievances but does not detail which specific decisions caused the most outrage.
Twin earthquakes struck Venezuela in an unusual but not unprecedented seismic event. Scientists are already collecting data to build a more detailed picture of what caused the quakes. Such paired tremors provide valuable information about the region's geological structure and help predict future hazards.
A new Gedeon Richter report on Polish attitudes to longevity finds that 85% of respondents want a long life, but only if it involves social connection. More than half reject the idea of immortality if it comes with suffering, dependency or loss of physical and mental fitness. Young adults report feeling lonelier and more anxious about the future than seniors do.
Anna Lewandowska, trainer and wife of Robert Lewandowski, posted bikini photos on Instagram showing off her toned physique. She took advantage of the warm June weather to share the images, adding a short caption to the post. The post quickly drew attention from her followers.
Thursday's session on the Warsaw Stock Exchange brought a long-awaited rebound from recent losses, driven by strong financial results and optimistic forecasts from US chip giant Micron. Analysts noted that Poland's market category is heavily dependent on sentiment in the semiconductor sector. The biggest gains were recorded in the energy and clothing sectors.
On June 25, 2024, Kenyan protesters stormed parliament during mass youth demonstrations against economic hardship and corruption. An annual march is now held on that date to remember those killed during the unrest. Frustration with President William Ruto's government continues to grow.
Indiana Pacers star guard Tyrese Haliburton spoke with The Hollywood Reporter about his lengthy recovery from injury, saying "Oh God, it's been a long year." He described watching the New York Knicks win from his couch while sidelined. Haliburton also touched on his plans in Hollywood during the interview.
Ford implemented an artificial intelligence system to assess the quality of its vehicles, but the tool proved unreliable. The company was forced to apologise to its engineers for mistakes made by the AI system. The case highlights the risks of entrusting critical manufacturing processes to algorithms without adequate oversight.
Comments
Loading…
Swipe up
⚡
You're all caught up
You've seen all the latest stories. Check back later for more.
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!