[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHJk0Mr1x5YbIfVjud909k21HWMpYoM0ot_sOHAPOPTk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"4af42ad3-79ee-4e6d-92bc-07646edddec4","malicious-edge-extension-abuses-native-messaging-to-deploy-ransomware","6071f09d-112e-473e-b9c4-07a8073c3e7a","Malicious Edge Extension Abuses Native Messaging to Deploy Ransomware","Attackers distributed a malicious Microsoft Edge extension ('Edgecution') by impersonating IT support staff on Microsoft Teams, tricking users into downloading what appeared to be a legitimate software update. The extension exploited the Chrome Native Messaging protocol — a legitimate browser feature — to escape the browser sandbox and install a Python-based backdoor, effectively turning a trusted mechanism into an attack vector. This attack succeeded largely because users lacked awareness of social engineering tactics and organizations failed to restrict which browser extensions could be installed or which native messaging hosts were permitted. The abuse of trusted internal communication platforms like Teams amplifies the risk, as employees are conditioned to trust IT-related messages received there. This highlights how attackers increasingly weaponize legitimate software features and trusted channels to evade both technical controls and user suspicion.","**Immediate actions:**\n- Audit and restrict browser extension installations to an approved allowlist via Group Policy or MDM for all managed devices.\n- Disable or restrict Native Messaging host permissions for browsers where the feature is not required for business operations.\n- Alert employees to verify any IT support requests received via Teams through a secondary, confirmed channel before downloading software.\n\n**Long-term improvements:**\n- Enforce application allowlisting to prevent unauthorized Python interpreters or scripts from executing on endpoints.\n- Implement Microsoft Teams governance policies that restrict external contacts and flag messages containing download links for review.\n- Establish a formal browser hardening baseline (e.g., based on CIS Benchmarks for Edge\u002FChrome) and enforce it across all managed endpoints.\n\n**Detection measures:**\n- Monitor for unusual Native Messaging host registrations and unexpected parent-child process relationships spawned from browser processes.\n- Deploy endpoint detection and response (EDR) tooling configured to alert on Python script execution in user-writable directories.\n- Log and review all Teams messages containing external URLs and correlate with subsequent download or execution events on endpoints.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 9: Email and Web Browser Protections","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AT-2: Literacy Training and Awareness","NIST SP 800-53 AC-6: Least Privilege","MITRE ATT&CK T1176: Browser Extensions","MITRE ATT&CK T1559: Inter-Process Communication (Native Messaging)","MITRE ATT&CK T1566.002: Phishing – Spearphishing Link","NIST CSF DE.CM-1: Network Monitoring","GDPR Article 32: Security of Processing (where PII may be exfiltrated)","published","2026-06-24T22:21:06.274731+00:00","2026-06-24T22:21:06.147+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmalicious-edge-extension-abuses-native-messaging-as-bridge-to-malware\u002F","malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware-9fda4c","Malicious Edge extension abuses Native Messaging as bridge to malware",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":46,"name":47,"slug":48,"description":49,"color":50},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]