Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Edge Extension Malware Exploits Chrome Protocol

Edge Extension Malware Exploits Chrome Protocol

Posted on June 24, 2026 By CWS

A recently exposed malware campaign reveals a sophisticated threat leveraging a browser extension to compromise computer systems. Security experts have discovered that a malicious Microsoft Edge extension is being used to bypass the browser’s security measures, allowing attackers direct access to victims’ computers.

Security Breach via Microsoft Teams

This alarming campaign is linked to an initial access broker associated with the Payouts King ransomware syndicate, highlighting the advanced nature of browser-based attacks today. The attackers reach their targets through Microsoft Teams, posing as IT personnel, and instructing victims to update their spam filters.

Victims are then misdirected to a counterfeit Microsoft website, which provides fraudulent download links labeled as Outlook updates. These downloads covertly install malware on the unsuspecting user’s machine, evading immediate detection.

Edgecution: A Stealthy Threat

Zscaler ThreatLabz analysts have been monitoring this operation, dubbing the malware ‘Edgecution.’ Their report indicates that the malware operates through a dual-component structure, enabling comprehensive control over the compromised system. Individually, these components might not trigger alarms, but together they establish a formidable backdoor.

The fake website masquerades as an ‘Outlook Updates Management Console,’ offering three infection vectors: an AutoHotKey script, a Windows batch script, and a PowerShell script. Each method results in a hidden Edge browser session, silently activating the malicious extension without alerting the user.

Exploiting Chrome’s Native Messaging

The campaign exploits Chrome’s native messaging protocol, intended for safe communication between browser extensions and trusted applications. Edgecution subverts this protocol to send commands from the extension to a Python backdoor on the host machine, bypassing the browser’s sandbox restrictions.

A native messaging manifest registers a fake application called ‘Edge Monitoring Agent,’ allowing it to relay commands from the attacker’s control server to the backdoor. This communication is facilitated through the chrome.runtime.sendNativeMessage API call, enabling the backdoor to execute unauthorized activities.

Advanced Evasion Techniques

The Python backdoor is equipped to execute shell commands, write files, run PowerShell scripts, list processes, and execute custom Python code. It processes each command in JSON format, ensuring stealth by shutting down immediately after execution to avoid detection by security software.

To further conceal its presence, the malware stores a decryption key in the Windows registry, keeping its strings encrypted. The extension operates in a headless Edge window, and all command and control (C2) traffic is routed through Amazon CloudFront subdomains, mimicking legitimate cloud activity.

Security Recommendations

Zscaler advises organizations to closely monitor browser extension installations and enforce strict controls over native messaging host configurations. Educating users to recognize phishing attempts impersonating IT staff is crucial. A multilayered defense strategy remains the best safeguard against such intricate threats combining social engineering with advanced technical exploits.

Indicators of compromise include specific URLs and SHA256 hashes related to the Edgecution malware. These details are essential for cybersecurity teams to identify and mitigate potential risks.

Cyber Security News Tags:browser security, Chrome protocol, Cybersecurity, Edge extension, Edgecution, IT security, Malware, Native Messaging, phishing attacks, Python backdoor, Ransomware, social engineering, threat analysis, Zscaler

Post navigation

Previous Post: LastPass, BeyondTrust Affected by Klue Data Breach
Next Post: Mistic Backdoor Evades Detection Using Microsoft Tools

Related Posts

Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’ Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’ Cyber Security News
Kenyan Filmmakers Installed With FlexiSPY Spyware That Monitors Messages and Social Media Kenyan Filmmakers Installed With FlexiSPY Spyware That Monitors Messages and Social Media Cyber Security News
Microsoft December 2025 Patch Tuesday Microsoft December 2025 Patch Tuesday Cyber Security News
SecSuite: Comprehensive AI-Driven Security Platform Unveiled SecSuite: Comprehensive AI-Driven Security Platform Unveiled Cyber Security News
Cloud Security Essentials – Protecting Multi-Cloud Environments Cloud Security Essentials – Protecting Multi-Cloud Environments Cyber Security News
Cybercriminals Exploit Screen-Sharing to Steal Legal Data Cybercriminals Exploit Screen-Sharing to Steal Legal Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Rust-Based macOS Threat Uses Telegram for Data Theft
  • AWS Phishing Kit Exploits MFA for Real-Time Access
  • Russia’s Use of Cellebrite to Access Activist’s iPhone
  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Rust-Based macOS Threat Uses Telegram for Data Theft
  • AWS Phishing Kit Exploits MFA for Real-Time Access
  • Russia’s Use of Cellebrite to Access Activist’s iPhone
  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark