Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Edge Extension Malware Exploits Chrome Protocol

Edge Extension Malware Exploits Chrome Protocol

Posted on June 24, 2026 By CWS

A recently exposed malware campaign reveals a sophisticated threat leveraging a browser extension to compromise computer systems. Security experts have discovered that a malicious Microsoft Edge extension is being used to bypass the browser’s security measures, allowing attackers direct access to victims’ computers.

Security Breach via Microsoft Teams

This alarming campaign is linked to an initial access broker associated with the Payouts King ransomware syndicate, highlighting the advanced nature of browser-based attacks today. The attackers reach their targets through Microsoft Teams, posing as IT personnel, and instructing victims to update their spam filters.

Victims are then misdirected to a counterfeit Microsoft website, which provides fraudulent download links labeled as Outlook updates. These downloads covertly install malware on the unsuspecting user’s machine, evading immediate detection.

Edgecution: A Stealthy Threat

Zscaler ThreatLabz analysts have been monitoring this operation, dubbing the malware ‘Edgecution.’ Their report indicates that the malware operates through a dual-component structure, enabling comprehensive control over the compromised system. Individually, these components might not trigger alarms, but together they establish a formidable backdoor.

The fake website masquerades as an ‘Outlook Updates Management Console,’ offering three infection vectors: an AutoHotKey script, a Windows batch script, and a PowerShell script. Each method results in a hidden Edge browser session, silently activating the malicious extension without alerting the user.

Exploiting Chrome’s Native Messaging

The campaign exploits Chrome’s native messaging protocol, intended for safe communication between browser extensions and trusted applications. Edgecution subverts this protocol to send commands from the extension to a Python backdoor on the host machine, bypassing the browser’s sandbox restrictions.

A native messaging manifest registers a fake application called ‘Edge Monitoring Agent,’ allowing it to relay commands from the attacker’s control server to the backdoor. This communication is facilitated through the chrome.runtime.sendNativeMessage API call, enabling the backdoor to execute unauthorized activities.

Advanced Evasion Techniques

The Python backdoor is equipped to execute shell commands, write files, run PowerShell scripts, list processes, and execute custom Python code. It processes each command in JSON format, ensuring stealth by shutting down immediately after execution to avoid detection by security software.

To further conceal its presence, the malware stores a decryption key in the Windows registry, keeping its strings encrypted. The extension operates in a headless Edge window, and all command and control (C2) traffic is routed through Amazon CloudFront subdomains, mimicking legitimate cloud activity.

Security Recommendations

Zscaler advises organizations to closely monitor browser extension installations and enforce strict controls over native messaging host configurations. Educating users to recognize phishing attempts impersonating IT staff is crucial. A multilayered defense strategy remains the best safeguard against such intricate threats combining social engineering with advanced technical exploits.

Indicators of compromise include specific URLs and SHA256 hashes related to the Edgecution malware. These details are essential for cybersecurity teams to identify and mitigate potential risks.

Cyber Security News Tags:browser security, Chrome protocol, Cybersecurity, Edge extension, Edgecution, IT security, Malware, Native Messaging, phishing attacks, Python backdoor, Ransomware, social engineering, threat analysis, Zscaler

Post navigation

Previous Post: LastPass, BeyondTrust Affected by Klue Data Breach
Next Post: Mistic Backdoor Evades Detection Using Microsoft Tools

Related Posts

Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code Cyber Security News
Hackers Hijacking IIS Servers in The Wild Using Exposed ASP .NET Machine Keys to Inject Malicious Modules Hackers Hijacking IIS Servers in The Wild Using Exposed ASP .NET Machine Keys to Inject Malicious Modules Cyber Security News
SpyCloud Unveils Top 10 Cybersecurity Predictions Poised to Disrupt Identity Security in 2026 SpyCloud Unveils Top 10 Cybersecurity Predictions Poised to Disrupt Identity Security in 2026 Cyber Security News
Android Malware Alert: MiningDropper’s Dangerous Impact Android Malware Alert: MiningDropper’s Dangerous Impact Cyber Security News
ATHR Platform Revolutionizes Large-Scale Vishing Attacks ATHR Platform Revolutionizes Large-Scale Vishing Attacks Cyber Security News
Microsoft’s April 2026 Update Strengthens Windows 11 Security Microsoft’s April 2026 Update Strengthens Windows 11 Security Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious Extension Mimics Google Translate, Compromises Browsers
  • OpenAI’s Astra Sparks Cybersecurity Worries
  • Secure AI-Driven Development: Webinar Insights
  • CEVA Logistics Breach Exposes Steam Hardware Buyers
  • Stealthium Enhances Security for AI Accelerators and Neo-Clouds

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious Extension Mimics Google Translate, Compromises Browsers
  • OpenAI’s Astra Sparks Cybersecurity Worries
  • Secure AI-Driven Development: Webinar Insights
  • CEVA Logistics Breach Exposes Steam Hardware Buyers
  • Stealthium Enhances Security for AI Accelerators and Neo-Clouds

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark