Zscaler: fake IT support on Teams gives attackers a foothold via the browser

Zscaler has analysed Edgecution, a new malware campaign tied to an initial access broker associated with the Payouts King ransomware group. The attack starts with social engineering, often through Microsoft Teams messages in which the attacker poses as IT support, leading the victim to a fake Microsoft update page. From there a hidden Microsoft Edge extension and a Python backdoor are installed. The extension talks to the attacker's command-and-control server, while the backdoor grants deeper access to the machine, including collecting system information, browsing the filesystem, launching processes and running commands. The core of the technique is abuse of the browser's native messaging feature to break out of the browser sandbox.

What this means for your organisation

Teams is perceived as an internal channel, and a message that appears to come from IT carries high credibility. Once the foothold is established, this is preparation for a ransomware attack rather than the end goal. A browser extension is also somewhere few organisations think to look for malicious code.

Berigo recommends

  • Restrict who can message your staff in Teams from external accounts.
  • Manage browser extensions with an allowlist, and alert when anything outside the list is installed.
  • Establish one known and communicated channel for contact from IT, so staff have something to check against.
  • Monitor native messaging configurations and new Python processes on client machines.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch