Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
Summary
Hide ▲
Show ▼
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based backdoor. The activity matters because it turns a browser extension into a bridge for shell, PowerShell, and arbitrary Python execution on infected systems. The delivery chain uses fake Microsoft Teams IT-support lures and update-themed pages to push malicious scripts and ZIP payloads. The operation is tied to ransomware-related access tooling and is designed to increase persistence and control on compromised Windows hosts.
Related Happenings
Silent Swap browser-extension clipboard clipper
Malware Activity
H score36
First: 30.06.2026 18:40
Last: 30.06.2026 18:40
Sources 1
About this happening:
The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
Silent Swap browser-extension clipboard clipper
Malware ActivityAbout this happening: The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
Silent Swap browser-extension crypto-theft campaign
Campaign
H score36
First: 30.06.2026 18:40
Last: 30.06.2026 18:40
Sources 1
About this happening:
The Silent Swap campaign is replacing copied cryptocurrency wallet addresses with attacker-controlled ones, creating a risk of permanent financial loss for crypto users. I...
Silent Swap browser-extension crypto-theft campaign
CampaignAbout this happening: The Silent Swap campaign is replacing copied cryptocurrency wallet addresses with attacker-controlled ones, creating a risk of permanent financial loss for crypto users. I...
Search for perplexity ai malicious Chrome extension
Malware Activity
H score29
First: 29.06.2026 21:40
Last: 29.06.2026 21:40
Sources 1
About this happening:
A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Search for perplexity ai malicious Chrome extension
Malware ActivityAbout this happening: A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
StegoAd malicious Edge extension operation
Malware Activity
H score19
First: 29.06.2026 11:32
Last: 29.06.2026 11:32
Sources 1
About this happening:
The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
StegoAd malicious Edge extension operation
Malware ActivityAbout this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware Activity
H score16
First: 28.05.2026 00:31
Last: 28.05.2026 00:31
Sources 1
About this happening:
A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware ActivityAbout this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
Timeline
-
24.06.2026 23:58 2 articles · 21d ago
Edgecution escapes the Microsoft Edge sandbox and launches a Python backdoor
Initial DisclosureZscaler identifies Edgecution, a malicious Microsoft Edge extension linked to an initial access broker tied to Payouts Kings, as a browser-to-host malware chain that starts with Microsoft Teams IT-support lures and fake Microsoft update pages and ends with Chrome Native Messaging launching a Python-based backdoor on compromised Windows hosts.
Show sources
- Malicious Edge extension abuses Native Messaging as bridge to malware — www.bleepingcomputer.com — 24.06.2026 23:58
- Malicious Edge extension abuses Native Messaging as bridge to malware — www.bleepingcomputer.com — 24.06.2026 23:58