Find notable cyber news and cases, enriched with sources, timelines, and signals.

Edgecution malicious Microsoft Edge extension backdoor activity

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based backdoor. The activity matters because it turns a browser extension into a bridge for shell, PowerShell, and arbitrary Python execution on infected systems. The delivery chain uses fake Microsoft Teams IT-support lures and update-themed pages to push malicious scripts and ZIP payloads. The operation is tied to ransomware-related access tooling and is designed to increase persistence and control on compromised Windows hosts.

Related Happenings

Silent Swap browser-extension clipboard clipper

Malware Activity
H score36 First: 30.06.2026 18:40 Last: 30.06.2026 18:40 Sources 1

About this happening: The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...

Silent Swap browser-extension crypto-theft campaign

Campaign
H score36 First: 30.06.2026 18:40 Last: 30.06.2026 18:40 Sources 1

About this happening: The Silent Swap campaign is replacing copied cryptocurrency wallet addresses with attacker-controlled ones, creating a risk of permanent financial loss for crypto users. I...

Search for perplexity ai malicious Chrome extension

Malware Activity
H score29 First: 29.06.2026 21:40 Last: 29.06.2026 21:40 Sources 1

About this happening: A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...

StegoAd malicious Edge extension operation

Malware Activity
H score19 First: 29.06.2026 11:32 Last: 29.06.2026 11:32 Sources 1

About this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

Timeline

  1. 24.06.2026 23:58 2 articles · 21d ago

    Edgecution escapes the Microsoft Edge sandbox and launches a Python backdoor

    Initial Disclosure

    Zscaler identifies Edgecution, a malicious Microsoft Edge extension linked to an initial access broker tied to Payouts Kings, as a browser-to-host malware chain that starts with Microsoft Teams IT-support lures and fake Microsoft update pages and ends with Chrome Native Messaging launching a Python-based backdoor on compromised Windows hosts.

    Show sources