Malicious Edge extension abuses Native Messaging as bridge to malware
In a ransomware assault, a malicious Microsoft Edge extension known as "Edgecution" was utilized to break out of the browser sandbox and install a Python-based backdoor.
The Chrome Native Messaging protocol, which enables browser extensions to communicate with native desktop applications—for example, a password manager interacting with the extension to complete online forms—is used to gain access to the local system.
This enables the browser to interact with the native application via standard input/output data streams and launch it as a distinct process. Under the guise of deploying a spam filter update, an Edgecution compromise starts with the attacker pretending to be an IT support staff member on Microsoft Teams and sending staff members to a false page read more about Malicious...

