{
  "Event": {
    "analysis": "1",
    "date": "2026-06-23",
    "extends_uuid": "",
    "info": "[Threat Intel] Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware",
    "protected": false,
    "publish_timestamp": "1782533530",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1782533529",
    "uuid": "5410fc07-3653-42b5-9e21-fd0c777a0dd8",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#6dbaba",
        "local": false,
        "name": "misp-galaxy:producer=\"Zscaler\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#705cef",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Scheduled Task - T1053.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#029dd6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Software Extensions - T1176\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5a258",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#bf01b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Modify Registry - T1112\"",
        "relationship_type": ""
      },
      {
        "colour": "#0c0051",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"",
        "relationship_type": ""
      },
      {
        "colour": "#3780c6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"",
        "relationship_type": ""
      },
      {
        "colour": "#62f4c1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Discovery - T1057\"",
        "relationship_type": ""
      },
      {
        "colour": "#755c09",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b95cd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"",
        "relationship_type": ""
      },
      {
        "colour": "#4bc785",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Hollowing - T1055.012\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#356c41",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Encrypted Channel - T1573\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d37d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Python - T1059.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#07a4a1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Encoding - T1132\"",
        "relationship_type": ""
      },
      {
        "colour": "#02475d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:ransomware=\"payoutsking\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#f1dfed",
        "local": false,
        "name": "rectifyq:TA-category=\"Ransomware\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782442836",
        "to_ids": false,
        "type": "link",
        "uuid": "3020ebf1-3331-431b-9a05-c4333754da36",
        "value": "https://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782442836",
        "to_ids": false,
        "type": "text",
        "uuid": "a6c8f03b-7ce8-4b8a-b37d-74285cb88291",
        "value": "An initial access broker linked to Payouts King ransomware is deploying Edgecution, a sophisticated malware utilizing a malicious Microsoft Edge browser extension. The attack begins through social engineering via Microsoft Teams, impersonating IT staff and directing victims to fake Microsoft websites offering supposed Outlook updates. Edgecution comprises two components: a browser extension that communicates with command-and-control servers via websockets, and a Python-based backdoor. The extension abuses Chrome native messaging protocol to escape browser sandbox restrictions, enabling direct host access. This allows attackers to manipulate the filesystem, launch processes, and execute arbitrary code. The malware operates in a headless browser, remaining invisible to users. Deployment methods include AutoHotKey scripts, Windows batch scripts, and PowerShell scripts. The Python backdoor supports various commands including system information collection, filesystem access, and arbitrary code execution."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782442836",
        "to_ids": false,
        "type": "text",
        "uuid": "734d1e6d-e912-415e-b0ef-e82630915c12",
        "value": "Name: Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware\nAuthor: AlienVault\nAdversary: Payouts King\nTags: [\"browser extension\", \"social engineering\", \"python backdoor\", \"initial access broker\", \"edgecution\"]\nTgtd countries: []\nMlwr families: [\"Edgecution\"]\nAttack_ids: [\"T1053.005\", \"T1082\", \"T1176\", \"T1106\", \"T1140\", \"T1055\", \"T1112\", \"T1083\", \"T1204\", \"T1057\", \"T1059.001\", \"T1547.001\", \"T1566\", \"T1055.012\", \"T1027\", \"T1573\", \"T1059.006\", \"T1132\", \"T1059.003\", \"T1071.001\", \"T1105\"]\nIndustries: []"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782442836",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "c2943f6f-a71c-4e28-bf0f-20655c6a55d6",
        "value": "Payouts King"
      },
      {
        "category": "Payload delivery",
        "comment": "Edgecution Python backdoor No sample in VT\r\nLast check:27/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782527983",
        "to_ids": true,
        "type": "sha256",
        "uuid": "210b82c0-74be-414d-be43-72a6e2cb6dbc",
        "value": "3d1158884fb339b3328bd330fcc27598e1f1c94bcac39e75d1a272afa4deee1a",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "Edgecution browser extension (background.js) No sample in VT\r\nLast check:27/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782527984",
        "to_ids": true,
        "type": "sha256",
        "uuid": "35a138c0-7938-4684-9824-5373eeafbe13",
        "value": "a08d8e63b0cd3638fb40b8e6da546e26da69439597565827f9cec87915f78568",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Edgecution C2 server",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782529197",
        "to_ids": true,
        "type": "url",
        "uuid": "bf33e253-c49e-4cef-8f61-53403a42b305",
        "value": "wss://d3nh8sl98s2554.cloudfront.net/ws",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Edgecution C2 server",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782529219",
        "to_ids": true,
        "type": "url",
        "uuid": "55967848-1d84-4595-9686-a26d28fe26d3",
        "value": "wss://d2g6dl71gua1qa.cloudfront.net/ws",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Edgecution C2 server",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782529240",
        "to_ids": true,
        "type": "url",
        "uuid": "cccb0d1c-dd9a-463c-8c72-99c3a9316d6a",
        "value": "wss://d1jp293q9tvi92.cloudfront.net/ws",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Edgecution C2 server",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782529262",
        "to_ids": true,
        "type": "url",
        "uuid": "214d7471-6aab-4164-acb0-2fdafbc84170",
        "value": "wss://d23l50n6ubud7p.cloudfront.net/ws",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}