Edgecution: Malicious Edge Extension Backdoor
ID: 2060ccab-35ec-5821-a5d9-986d1aabb66b
STIX ID: report--2060ccab-35ec-5821-a5d9-986d1aabb66b
Feed Name: Zscaler Security Research Blog
This report analyzes "Edgecution": a sophisticated attack that deploys a malicious Microsoft Edge extension and an embedded Python backdoor via social-engineered Microsoft Teams messages and a fake Outlook updates site. The extension uses Chrome native messaging to invoke a bundled Python interpreter (bypassing the browser sandbox), establishes persistence by launching Edge in headless mode with a loaded extension, communicates with CloudFront-hosted C2 over websockets, and supports commands for system info collection, remote shell execution, file writes, running Python or PowerShell code, and process enumeration—enabling broad remote control of infected hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
