Malicious Edge extension abuses Native Messaging as bridge to malware
ID: 5fb0d822-09d0-5604-9dc0-74f9d631875e
STIX ID: report--5fb0d822-09d0-5604-9dc0-74f9d631875e
Feed Name: Bleeping Computer
A malicious Microsoft Edge extension named 'Edgecution' has been used in a ransomware-related campaign to escape the browser sandbox by abusing Chrome Native Messaging and launching a bundled Python 3.13.3 backdoor on victims' hosts. Initial access is gained through social-engineering (fake Microsoft update site promoted via Microsoft Teams) that drops a malformed ZIP containing an Edge extension and native host components; the extension runs headless, communicates with a local Python backdoor to execute shell/PowerShell/Python code, enumerate systems, write files, and maintain persistence. Zscaler links the activity to an initial access broker associated with the Payouts Kings ransomware operation and provides IoCs (C2 servers, hashes) and recommendations to monitor extensions and native messaging host configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
