<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware-jv6gql7ie" -->

---
title: Malicious Edge extension abuses Native Messaging as...
description: A malicious Microsoft Edge extension called &#x27;Edgecution&#x27; has been discovered abusing Chrome&#x27;s Native Messaging protocol to escape the browser sandbox and...
canonical: https://daily.dev/posts/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware-jv6gql7ie
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Malicious Edge extension abuses Native Messaging as bridge to malware | daily.dev
og:description: A malicious Microsoft Edge extension called &#x27;Edgecution&#x27; has been discovered abusing Chrome&#x27;s Native Messaging protocol to escape the browser sandbox and...
og:url: https://daily.dev/posts/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware-jv6gql7ie
og:image: https://api.daily.dev/og/posts/Jv6gql7IE.png
og:image:alt: Malicious Edge extension abuses Native Messaging as bridge to malware
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Malicious Edge extension abuses Native Messaging as bridge to malware

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

A malicious Microsoft Edge extension called 'Edgecution' has been discovered abusing Chrome's Native Messaging protocol to escape the browser sandbox and deploy a Python-based backdoor. The attack chain begins with social engineering via Microsoft Teams, where attackers pose as IT support and direct victims to a fake Microsoft update page. From there, multiple scripts (AutoHotKey, batch, PowerShell) deploy the malware, which runs in a headless Edge browser and communicates with a local Python backdoor capable of executing shell commands, running PowerShell, writing files, and gathering system information. Zscaler researchers link the campaign to an initial access broker connected to the Payouts Kings ransomware operation. Organizations are advised to monitor browser extensions and enforce strict native messaging host controls.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware>

## Similar posts on daily.dev

- [Newly discovered malicious extensions could be lurking in enterprise browsers](https://daily.dev/posts/newly-discovered-malicious-extensions-could-be-lurking-in-enterprise-browsers-i20gceevx) · CSO Online · 0 upvotes · 0 comments
- [New Malware turns Microsoft cloud into its control center](https://daily.dev/posts/new-malware-turns-microsoft-cloud-into-its-control-center-gwsh3laj6) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#python](https://daily.dev/tags/python), [#devtools](https://daily.dev/tags/devtools), [#ransomware](https://daily.dev/tags/ransomware), [#microsoft-edge](https://daily.dev/tags/microsoft-edge)

[View this post on daily.dev](https://daily.dev/posts/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware-jv6gql7ie)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Malicious Edge extension abuses Native Messaging as bridge to malware","url":"https://daily.dev/posts/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware-jv6gql7ie","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware-jv6gql7ie"},"datePublished":"2026-06-24T21:01:03.904Z","dateModified":"2026-06-24T21:02:32.496Z","description":"A malicious Microsoft Edge extension called 'Edgecution' has been discovered abusing Chrome's Native Messaging protocol to escape the browser sandbox and...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c1d269411199391b3b8c873225bcc49e?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c1d269411199391b3b8c873225bcc49e?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware-jv6gql7ie","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"python,devtools,ransomware,microsoft-edge","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Malicious Edge extension abuses Native Messaging as bridge to malware"}]}
```

