Back to all lessons
Awareness Lessons
4 months ago

Malicious Edge Extension Abuses Native Messaging to Deploy Ransomware

Attackers distributed a malicious Microsoft Edge extension ('Edgecution') by impersonating IT support staff on Microsoft Teams, tricking users into downloading what appeared to be a legitimate software update. The extension exploited the Chrome Native Messaging protocol — a legitimate browser feature — to escape the browser sandbox and install a Python-based backdoor, effectively turning a trusted mechanism into an attack vector. This attack succeeded largely because users lacked awareness of social engineering tactics and organizations failed to restrict which browser extensions could be installed or which native messaging hosts were permitted. The abuse of trusted internal communication platforms like Teams amplifies the risk, as employees are conditioned to trust IT-related messages received there. This highlights how attackers increasingly weaponize legitimate software features and trusted channels to evade both technical controls and user suspicion.

Tactical Insight

Immediate actions

  • Audit and restrict browser extension installations to an approved allowlist via Group Policy or MDM for all managed devices.
  • Disable or restrict Native Messaging host permissions for browsers where the feature is not required for business operations.
  • Alert employees to verify any IT support requests received via Teams through a secondary, confirmed channel before downloading software.

Long-term improvements

  • Enforce application allowlisting to prevent unauthorized Python interpreters or scripts from executing on endpoints.
  • Implement Microsoft Teams governance policies that restrict external contacts and flag messages containing download links for review.
  • Establish a formal browser hardening baseline (e.g., based on CIS Benchmarks for Edge/Chrome) and enforce it across all managed endpoints.

Detection measures

  • Monitor for unusual Native Messaging host registrations and unexpected parent-child process relationships spawned from browser processes.
  • Deploy endpoint detection and response (EDR) tooling configured to alert on Python script execution in user-writable directories.
  • Log and review all Teams messages containing external URLs and correlate with subsequent download or execution events on endpoints.