Malicious Microsoft Edge extension used Native Messaging to install a Python backdoor in ransomware-linked attacks

Attackers used a fake Microsoft Edge update process to trick employees into installing a malicious browser extension that helped deploy malware on their computers. Zscaler says the 'Edgecution' campaign starts with Microsoft Teams messages from fake IT support and uses Chrome Native Messaging in Microsoft Edge to let the extension communicate with a local Python-based backdoor outside the browser sandbox. The activity is linked by tactics and infrastructure patterns to an initial access broker associated with the Payouts Kings ransomware operation.
Why it matters: This matters because it turns a browser extension into a bridge for full system compromise, not just in-browser abuse, and it is being used in real ransomware-linked intrusions. Organizations should warn users about fake IT support messages, restrict extension installs, and monitor or lock down Native Messaging host configurations on managed endpoints.

Sources

Malicious Edge extension abuses Native Messaging as bridge to malware
Bill Toulas 2026.06.24 100% relevant
This article establishes a distinct new story because it introduces the Edgecution malware campaign, its Edge Native Messaging technique, and its reported link to a Payouts Kings-associated initial access broker rather than updating a previously tracked event.
← Back to all stories