logo

Malicious Edge extension abuses Native Messaging as bridge to malware

ID: 5fb0d822-09d0-5604-9dc0-74f9d631875e

STIX ID: report--5fb0d822-09d0-5604-9dc0-74f9d631875e

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Bill Toulas

...
...

A malicious Microsoft Edge extension named 'Edgecution' has been used in a ransomware-related campaign to escape the browser sandbox by abusing Chrome Native Messaging and launching a bundled Python 3.13.3 backdoor on victims' hosts. Initial access is gained through social-engineering (fake Microsoft update site promoted via Microsoft Teams) that drops a malformed ZIP containing an Edge extension and native host components; the extension runs headless, communicates with a local Python backdoor to execute shell/PowerShell/Python code, enumerate systems, write files, and maintain persistence. Zscaler links the activity to an initial access broker associated with the Payouts Kings ransomware operation and provides IoCs (C2 servers, hashes) and recommendations to monitor extensions and native messaging host configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.