logo

Malicious Edge Extension Uses Chrome Native Messaging to Execute Code on Victim Systems

ID: 00c22261-e54c-568b-a1e9-1d1f57f26c32

STIX ID: report--00c22261-e54c-568b-a1e9-1d1f57f26c32

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Tushar Subhra Dutta

...
...

A campaign named "Edgecution" uses Teams-based social engineering and a fake Microsoft update site to silently install a malicious Microsoft Edge extension that abuses Chrome native messaging to talk to a Python backdoor on the host, enabling full system compromise; the report includes C2 wss URLs, SHA256 hashes for the extension and backdoor, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.