Edgecution is a Windows backdoor comprising a malicious Microsoft Edge extension and a Python-based native messaging host. The extension maintains WebSocket command-and-control communications and relays instructions to the Python component through Chrome Native Messaging. This abuse of a legitimate browser integration mechanism enables host-level execution beyond browser sandbox restrictions without requiring a browser vulnerability. The backdoor supports arbitrary shell, PowerShell, and Python execution, filesystem access, file writing, process enumeration, and system and user information collection.
Deployment campaigns use Microsoft Teams messages impersonating internal IT support, often following email bombing, to direct victims to fraudulent Microsoft-branded update or verification pages. These pages deliver AutoHotkey, batch, or PowerShell deployment scripts, including clipboard-based execution workflows. Some intrusions also use Quick Assist to obtain hands-on access. Deployment has been associated with UNC6692, an initial access broker linked to Payouts King ransomware operations, and has been observed against a software-industry organization. Edgecution provides a foothold for follow-on ransomware activity rather than performing encryption itself.
Installation scripts reconstruct and extract a malformed encrypted archive containing the extension, native backdoor, and an embedded Python runtime. They register the native messaging host and establish scheduled-task persistence. The extension masquerades as an Edge Monitoring Agent and runs in a hidden or headless Edge instance using a separate browser profile. Evasion measures include obfuscated backdoor strings, a registry-stored decryption key, malformed archive headers, and short-lived Python processes that terminate after returning command results. Command-and-control traffic uses Amazon CloudFront infrastructure. The extension also implements tab and URL keyword monitoring functions, although its separate headless profile limits visibility into ordinary user browsing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Edgecution: malicious Microsoft Edge extension that escapes the browser sandbox to install a Python backdoor
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The final button in the page " Updates Registration " is utilized by the threat actors to capture the victim's Office 365 password.
The scripts repair a malformed ZIP archive, extract its files, configure a malicious Edge profile, and create a scheduled task that starts Microsoft Edge in headless mode.
Creates a Scheduled Task with description " Автозапуск {1dabdc99-69e0-45a6-9298-529419fa2fed} " configured to launch Microsoft Edge and load the Edgecution extension.
enables capabilities such as: arbitrary shell command execution, Python and PowerShell script execution
Arbitrary powershell commands (command 7) get wrapped into the command line shown in the next figure.
Zscaler describes three deployment options from the fake update page: an AutoHotKey script, a Windows batch script copied to the clipboard, and a PowerShell script copied to the clipboard.
enables capabilities such as: arbitrary shell command execution, Python and PowerShell script execution
The native messaging host component of Edgecution is critical and acts as the bridge between the Microsoft Edge extension and the underlying victim's host operating system.
The victim was instructed to launch Quick Assist and grant the threat actors access. Once connected, threat actors navigated to an Amazon S3-hosted phishing site and downloaded AutoHotkey along with a malicious AutoHotkey script, which was then executed to install Edgecution.
The scripts repair a malformed ZIP archive, extract its files, configure a malicious Edge profile, and create a scheduled task that starts Microsoft Edge in headless mode.
Creates a Scheduled Task with description " Автозапуск {1dabdc99-69e0-45a6-9298-529419fa2fed} " configured to launch Microsoft Edge and load the Edgecution extension.
The final button in the page " Updates Registration " is utilized by the threat actors to capture the victim's Office 365 password.
The scripts repair a malformed ZIP archive, extract its files, configure a malicious Edge profile, and create a scheduled task that starts Microsoft Edge in headless mode.
All strings in the stager are obfuscated by a single-byte XOR routine... The file in question was obfuscated through the free JavaScript obfuscation service Obfuscator.io.
attempt to deploy Edgecution, a malicious browser extension masquerading as "Edge Monitoring Agent."
Deletes itself with the following command: cmd /c start /min "" cmd /c timeout 4 & del "' A_AhkPath '" 2>nul & del "' A_ScriptFullPath '" & exit /b
Post-compromise activity frequently involved disabling endpoint security tools and harvesting credentials stored in browsers before ransomware deployment.
6 List running processes... Get-CimInstance Win32_Process | Select-Object ProcessId,ParentProcessId,Name,ExecutablePath,CommandLine
The extension side beacons to command-and-control infrastructure.
deobfuscating it reveals that it establishes a persistent WebSocket connection to the C2 server
This AutoHotkey script is the initial stager for Edgecution. It downloads a password-protected ZIP archive from AWS S3 containing Edgecution.
Multiple groups gained access by contacting employees via Microsoft Teams, posing as internal IT support, then guiding the target through a screen-sharing session to install a Remote Monitoring and Management (RMM) tool, such as AnyDesk/QuickAssist, or to execute a delivered payload.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser backdoor deployed via social-engineering-led initial access activity using Microsoft Teams impersonation and a forged software-update console.
A malicious Microsoft Edge extension paired with a Python-based native messaging host that escapes the browser sandbox to provide persistent backdoor access. It monitors visits to targeted websites in real time, communicates with C2 over WebSocket, fingerprints hosts, enumerates processes, writes files, and executes arbitrary shell, Python, and PowerShell commands on compromised machines.
A malicious Microsoft Edge browser-extension-based malware used in Teams phishing campaigns. It abuses the Chrome native messaging protocol to escape normal browser constraints, gain host access, manipulate the local filesystem, launch processes, and execute arbitrary code on the compromised system.
Malicious Microsoft Edge extension that abuses Chrome Native Messaging to communicate with a native Python-based backdoor on the host, bypass browser sandbox restrictions, connect to C2 infrastructure, and execute commands such as shell and PowerShell commands while collecting system information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.