Briefing

Malicious Edge extension abuses Native Messaging as bridge to malware

security
by Bill Toulas ·

Disable suspicious Edge extensions, block native messaging hosts, and monitor for malicious ZIP files.

What to do now

Disable suspicious Edge extensions, block native messaging hosts, and monitor for malicious ZIP files.

Summary

Microsoft Edge users are at risk from a malicious extension dubbed ‘Edgecution’, which was used in a ransomware attack to escape the browser sandbox and deploy a Python‑based backdoor. The extension exploits Chrome’s Native Messaging protocol, allowing it to launch a native application that runs with host‑level privileges. The malicious bundle includes a ZIP archive with malformed headers that contains a Python 3.13.3 backdoor and a malicious Edge extension disguised as an Edge Monitoring Agent. Attackers first trick users into downloading the extension via a fake Microsoft “Outlook Updates Management Console” that presents download buttons for an update pack, which then executes AutoHotKey, batch, or PowerShell scripts to configure the environment and create a scheduled task that runs Microsoft Edge. The backdoor receives commands from the extension and can execute shell commands, run PowerShell, run arbitrary Python code, write files, enumerate processes, and gather system information. The extension’s malicious component is limited to the browser sandbox, but the Python backdoor provides host‑level persistence and execution. Security researchers recommend strengthening monitoring of browser extensions and enforcing strict controls over native messaging host configurations to reduce the risk of compromise.

Key changes

  • Edgecution malicious extension uses Chrome Native Messaging to escape sandbox
  • Bundle contains malformed ZIP with Python 3.13.3 backdoor and malicious Edge extension
  • Fake Microsoft “Outlook Updates Management Console” delivers malicious scripts (AutoHotKey, batch, PowerShell)
  • Extension configures environment, creates scheduled task to run Edge
  • Backdoor can execute shell, PowerShell, Python, write files, enumerate processes, gather system info
  • Extension limited to sandbox; backdoor provides host‑level persistence
  • Researchers recommend monitoring browser extensions and controlling native messaging hosts
  • Attack demonstrates evolving ransomware techniques using browser extensions

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting