Malicious Chrome Extension Uses Native Messaging Host to Execute PowerShell Commands
5 Articles
5 Articles
The malware Edgecution is drawing the attention of the security community by exploring one of the most sensitive mechanisms of Chromium-based browsers. Discovered by researchers from Zscaler ThreatLabz, the threat combines a malicious extension of Microsoft Edge with a Python backdoor to create a bridge between the browser and the operating system, something that should normally be prevented by browser isolation layers. The case reinforces an in…
Malicious Chrome Extension Uses Native Messaging Host to Execute PowerShell Commands
Open the article to view the coverage from cybernoz.com
Malicious Edge extension abuses Native Messaging as bridge to malware | #ransomware | #cybercrime - National Cyber Security Consulting
A malicious Microsoft Edge extension dubbed ‘Edgecution' has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. Access to the local system is obtained by leveraging the Chrome Native Messaging protocol that allows browser extensions to interact with native desktop applications, such as a password manager communicating with […] Thank you for subscribing to our RSS feed! The post Malicious Edge exten…
Malicious Edge Extension Uses Chrome Native Messaging to Execute Code on Victim Systems
A new and deceptive malware campaign has been uncovered, one that turns an everyday browser extension into a dangerous tool for system compromise. Security researchers have identified a threat that uses a malicious Microsoft Edge extension to break out of the browser’s built-in security boundaries, giving attackers direct access to a victim’s computer. The campaign has been linked to an initial access broker with ties to the Payouts King ransomw…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium

