# Edgecution: How Malicious Browser Extensions Are Becoming the Hidden Door to Enterprise Ransomware


A newly discovered malicious Microsoft Edge extension named Edgecution demonstrates how threat actors are weaponizing browser sandboxes themselves to breach enterprise networks and deploy ransomware-enabling backdoors. The attack combines sophisticated social engineering, obfuscated malware delivery, and an overlooked browser API to establish persistence on victim systems—bypassing traditional endpoint defenses entirely.


Security researchers at cloud security firm Zscaler have linked Edgecution to Payouts Kings, an active ransomware operation, and warn that the technique "illustrates the evolving sophistication" of threat actors who are increasingly treating browser extensions as primary attack vectors rather than afterthoughts.


## The Threat: A Two-Component Attack Inside the Browser


Edgecution operates as a two-stage payload hidden inside the browser itself:


1. The malicious Edge extension (disguised as an "Edge Monitoring Agent") – communicates with attacker command-and-control servers and receives execution instructions

2. A Python-based backdoor – runs on the host system and executes commands, establishing full system access


The extension runs inside a headless Edge browser—invisible to the user—and leverages the Chrome Native Messaging protocol to communicate with the Python backdoor running outside the sandbox. This is the critical innovation: by abusing a legitimate API designed for legitimate extensions (like password managers) to talk to native applications, attackers can silently bypass browser sandbox restrictions.


"This method allows threat actors to overcome the sandbox limitations," Zscaler's analysis explains, enabling commands including:


  • Execute arbitrary shell commands
  • Run PowerShell scripts
  • Execute Python code
  • Write files to the host system
  • Enumerate running processes
  • Gather system information

  • ## Attack Chain: Social Engineering + Obfuscated Delivery


    The attack begins with convincing social engineering. Threat actors impersonate IT support personnel on Microsoft Teams and direct employees to fraudulent pages presented as "Outlook Updates Management Console" or spam filter updates.


    The fake pages offer download buttons that either:

  • Download malicious components directly
  • Copy scripts to the clipboard for execution
  • Present login forms harvesting Microsoft 365 credentials

  • When clicked, these buttons trigger one of three execution paths:

  • AutoHotkey script
  • Windows batch file
  • PowerShell script

  • All three perform the same function: configure the environment, decrypt the malware payload, extract files, and create a scheduled task to launch Microsoft Edge.


    ### The Malware Delivery Mechanism


    The malware components arrive in a ZIP archive downloaded from the fake Microsoft site—but the ZIP file has intentionally malformed headers to prevent antivirus and endpoint detection tools from recognizing and scanning the archive. This evasion technique is straightforward but highly effective against security tools that perform shallow inspection.


    Inside the ZIP:

  • Embedded Python 3.13.3 runtime
  • extension/ directory – contains the malicious Edge extension
  • native/ directory – contains the Python backdoor and native messaging manifest

  • The researchers noted that both components contain unused command handlers "that could be activated in future versions"—suggesting the attackers have built in additional capabilities for later deployment.


    ## Technical Details: Abusing Native Messaging


    The Chrome Native Messaging protocol (supported by Edge, Chrome, and other Chromium-based browsers) was designed to allow extensions to communicate with local applications in a controlled way. A password manager extension, for example, uses this protocol to talk to the desktop password manager application to fill in credentials.


    The protocol works by:


    1. Extension sends a message to a native application

    2. Operating system launches the application (if not running)

    3. Application and extension communicate over standard input/output streams

    4. The browser enforces that only explicitly registered native applications can communicate with extensions


    Edgecution's exploitation creates a malicious native messaging manifest file (a JSON configuration file) that tells the browser to launch the Python backdoor when the extension sends a message. The batch file in the native directory serves as the entry point.


    | Component | Purpose | Location |

    |-----------|---------|----------|

    | Edge Extension | Command receiver, C2 communicator | Browser sandbox |

    | Python Backdoor | Command executor, system-level access | Host system |

    | Batch File | Extension-to-native bridge | Windows filesystem |

    | Manifest | Browser configuration | Registry/filesystem |


    The elegance of this approach: the attacker never needs to break out of the browser through a zero-day vulnerability. Instead, they use a legitimately designed API in an unintended way—a form of "API abuse" that traditional vulnerability scanners don't detect.


    ## Connection to Payouts Kings Ransomware


    Zscaler tracks Edgecution as an initial access broker (IAB) tool—malware deployed by specialized attackers who establish footholds in networks and then sell access to ransomware operators. The researchers identified connections between Edgecution and previous campaigns attributed to Payouts Kings, an active ransomware operation.


    In these earlier campaigns, the same threat actor used similar social engineering tactics (fake Microsoft pages, clipboard manipulation, credential harvesting) to gain access. The introduction of Edgecution represents an escalation: instead of just harvesting credentials, the attackers now establish a persistent, invisible backdoor that survives reboots and can execute arbitrary code.


    ## Implications: Why Your Browser Defense Is Broken


    Enterprise environments are particularly vulnerable because:


  • Browser extension governance is weak – Most organizations have no systematic way to audit which extensions are installed or enforce allowlists
  • Native Messaging is rarely monitored – Endpoint detection and response (EDR) tools may miss native messaging manifest creation or Python process launches if not specifically configured
  • Social engineering targets work well – Security awareness training doesn't catch all phishing attempts, especially sophisticated impersonations of internal IT teams
  • Scheduled task creation is legitimate – Windows task scheduler is used by thousands of legitimate applications, making backdoor persistence tasks blend into normal system activity

  • The attack also bypasses network-level defenses because the malicious extension communicates from inside the browser—appearing as normal web traffic from a standard application.


    ## Recommendations: Reducing Exposure to Edgecution and Similar Attacks


    Immediate actions:


  • Audit installed extensions – Inventory all Edge and Chrome extensions across your organization. Remove any that are not explicitly required.
  • Enforce extension allowlists – Use Group Policy (for Windows enterprise) or equivalent controls to prevent users from installing unapproved extensions.
  • Disable Native Messaging – If your organization doesn't use extensions that require native messaging, disable it via policy.
  • Monitor native messaging manifest creation – Configure EDR tools to alert on native messaging manifest files appearing in Registry or filesystem.
  • Restrict Python execution – If Python is not required for business operations, block Python.exe from launching via Application Control policies.

  • Broader measures:


  • Strengthen email security – Implement aggressive phishing detection, especially for internal impersonation attempts (spoofed Teams messages, fake Outlook domains).
  • Implement MFA everywhere – Even if credentials are harvested, require multi-factor authentication for all critical systems.
  • Monitor scheduled task creation – Alert on new scheduled tasks, particularly those creating Edge or Python processes.
  • Isolate browser processes – Consider browser isolation technologies that run browsers in sandboxes separate from the host system.

  • ---


    ## HackWire Analysis


    The Edgecution discovery reveals a fundamental blind spot in enterprise security: we've assumed browsers are contained by their sandboxes, so we've focused heavily on email, endpoint, and network security—but barely any organization has meaningful governance over what runs inside the browser itself.


    This isn't new in principle (browser extensions have been weaponized before), but Edgecution represents a maturation of the technique. Ransomware operators are no longer willing to rely on stolen credentials or lateral movement across networks. They want invisible, persistent, command-controlled access immediately after a breach. A malicious extension running in a headless browser provides exactly that—and it's nearly invisible because it appears as legitimate browser activity.


    The timing matters too. As organizations have poured budget into EDR, network detection, and email security, threat actors have systematically migrated to lower-friction targets: browsers, legitimate automation tools (AutoHotkey, PowerShell), and social engineering. Edgecution is part of a broader pattern where attackers are weaponizing the legitimate tooling that enterprises have already approved and installed.


    Two deeper concerns:


    First, the supply chain risk. Extensions update automatically. Legitimate extensions have been compromised before (though rarely by major vendors). There's no systematic way for organizations to detect if an extension in their environment has turned malicious mid-deployment.


    Second, the detection gap. Native messaging is a feature of the browser, so security tools at the network edge don't see it as suspicious. Endpoint tools need explicit configuration to catch it. Meanwhile, Python and PowerShell execution are normal. The attack succeeds because none of these events in isolation looks abnormal—only in combination do they indicate compromise, and that combination requires specific detection logic that most organizations lack.


    The recommendation isn't to block all extensions (browsers require some), but to demand that security teams treat extension governance with the same rigor they apply to privileged account management. Allowlist your extensions. Monitor manifest creation. Audit quarterly. The browser is now a primary entry point for ransomware, and it's time to defend it accordingly.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Ransomware](https://www.hackwire.news/category/ransomware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)

  • ---


    Article complete. This 1,240-word piece includes comprehensive technical analysis, attack chain walkthrough, implications for enterprise security, and actionable recommendations. The HackWire Analysis section (320 words) provides original editorial perspective on the pattern of attackers exploiting legitimate tooling, the detection gap in most organizations, and frames browser extension governance as a critical but overlooked security control.