A malicious Microsoft Edge extension called 'Edgecution' has been discovered abusing Chrome's Native Messaging protocol to escape the browser sandbox and deploy a Python-based backdoor. The attack chain begins with social engineering via Microsoft Teams, where attackers pose as IT support and direct victims to a fake Microsoft update page. From there, multiple scripts (AutoHotKey, batch, PowerShell) deploy the malware, which runs in a headless Edge browser and communicates with a local Python backdoor capable of executing shell commands, running PowerShell, writing files, and gathering system information. Zscaler researchers link the campaign to an initial access broker connected to the Payouts Kings ransomware operation. Organizations are advised to monitor browser extensions and enforce strict native messaging host controls.

4m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
518 Impressions