logo

Edgecution: Malicious Edge Extension Backdoor

ID: 2060ccab-35ec-5821-a5d9-986d1aabb66b

STIX ID: report--2060ccab-35ec-5821-a5d9-986d1aabb66b

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2026-06-26

Date Updated: 2026-07-04

...
...

This report analyzes "Edgecution": a sophisticated attack that deploys a malicious Microsoft Edge extension and an embedded Python backdoor via social-engineered Microsoft Teams messages and a fake Outlook updates site. The extension uses Chrome native messaging to invoke a bundled Python interpreter (bypassing the browser sandbox), establishes persistence by launching Edge in headless mode with a loaded extension, communicates with CloudFront-hosted C2 over websockets, and supports commands for system info collection, remote shell execution, file writes, running Python or PowerShell code, and process enumeration—enabling broad remote control of infected hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.