{"id":573,"date":"2026-06-29T14:57:12","date_gmt":"2026-06-29T09:27:12","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=573"},"modified":"2026-08-18T15:00:42","modified_gmt":"2026-08-18T09:30:42","slug":"edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/","title":{"rendered":"Edgecution Turns Microsoft Edge Native Messaging Into a Ransomware Access Bridge"},"content":{"rendered":"<p>A newly discovered malware campaign dubbed Edgecution malware reveals how attackers can weaponize trusted browser features to gain host-level access. By combining Microsoft Teams phishing, a malicious Edge extension, and a Python backdoor, attackers transformed Microsoft Edge Native Messaging into a bridge between browser activity and ransomware deployment.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen Endpoint Security with Hexnode UEM<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the Edgecution malware attack works<\/h2>\n<p>The compromise begins with Microsoft Teams phishing rather than an exploit.<\/p>\n<p>Attackers impersonate internal IT support personnel and contact employees through Microsoft Teams. Victims are instructed to install what appears to be an Outlook spam-filter update from a fraudulent Microsoft Outlook Updates Management Console website.<\/p>\n<p>Instead of downloading a legitimate update, the site delivers one of several malicious installers:<\/p>\n<ul>\n<li>AutoHotKey scripts<\/li>\n<li>Windows batch scripts<\/li>\n<li>PowerShell scripts<\/li>\n<\/ul>\n<p>These scripts prepare the environment by repairing intentionally malformed ZIP headers, extracting malware components, and creating scheduled tasks that silently launch Microsoft Edge in headless mode.<\/p>\n<p>The downloaded package includes:<\/p>\n<table>\n<thead>\n<tr>\n<th>Component<\/th>\n<th>Purpose<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Embedded Python 3.13.3 runtime<\/td>\n<td>Executes the native backdoor<\/td>\n<\/tr>\n<tr>\n<td>extension directory<\/td>\n<td>Contains the malicious Microsoft Edge extension<\/td>\n<\/tr>\n<tr>\n<td>native directory<\/td>\n<td>Contains the native messaging host and Python backdoor<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This multi-stage design helps attackers avoid traditional detection mechanisms while establishing persistence.<\/p>\n<h2>Native Messaging becomes the attack bridge<\/h2>\n<p>Chrome Native Messaging is a legitimate Chromium feature designed to let trusted browser extensions communicate with native desktop applications.<\/p>\n<p>Organizations commonly use it for password managers, enterprise authentication tools, and other desktop integrations.<\/p>\n<p>Edgecution abuses this trusted mechanism.<\/p>\n<p>The installation scripts generate a Native Messaging manifest that registers a local application the browser extension can communicate with. Once the manifest exists, the malicious extension relays attacker commands directly to a Python process running outside the browser sandbox.<\/p>\n<p>Instead of exploiting a browser vulnerability, attackers misuse an approved communication channel to bridge browser activity and host-level execution.<\/p>\n<p>The malicious Edge extension runs inside an invisible headless Edge browser while communicating with the Python backdoor through the Native Messaging interface, making the attack significantly harder for users to notice.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Post-Hexnode-Live-Speaker.jpg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Cybersecurity Best Practices for Businesses to Adopt in 2026<\/h4><p>Explore cybersecurity best practices for 2026 to strengthen resilience against evolving cyber threats.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/cybersecurity-best-practices-2026-guide\/\" aria-label=\"Cybersecurity Best Practices for Businesses to Adopt in 2026\"><\/a><\/div><\/div><\/div>\n<h2>What the Python backdoor can do<\/h2>\n<p>The Python backdoor performs the actual malicious activity after receiving commands from the extension.<\/p>\n<p>Researchers observed capabilities including:<\/p>\n<ul>\n<li>Executing shell commands<\/li>\n<li>Running PowerShell commands<\/li>\n<li>Executing arbitrary Python code<\/li>\n<li>Writing files to the host<\/li>\n<li>Enumerating running processes<\/li>\n<li>Collecting detailed system information<\/li>\n<\/ul>\n<p>Because the extension serves primarily as a communication relay, the Python component carries out operations that would normally be impossible from within the browser sandbox.<\/p>\n<h2>Why this attack matters<\/h2>\n<p>Edgecution demonstrates that browser security extends far beyond preventing malicious websites.<\/p>\n<p>Modern enterprise attacks increasingly combine:<\/p>\n<ul>\n<li>Social engineering<\/li>\n<li>Trusted collaboration platforms<\/li>\n<li>Browser extension abuse<\/li>\n<li>Native Messaging<\/li>\n<li>Endpoint malware<\/li>\n<li>Ransomware initial access<\/li>\n<\/ul>\n<p>Each individual component appears legitimate in isolation. Together, they create an attack chain capable of bypassing traditional browser protections.<\/p>\n<p>Organizations should also strengthen browser extension security by restricting unauthorized extensions, limiting Native Messaging usage to trusted applications, validating IT support workflows conducted through Microsoft Teams, and monitoring scheduled task creation and scripting activity across managed endpoints.<\/p>\n<h2>How Hexnode helps defend against browser-to-host attacks<\/h2>\n<p>Browser threats rarely remain confined to the browser. They quickly evolve into endpoint compromise, making unified management and detection essential.<\/p>\n<p>Hexnode <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-unified-endpoint-management-uem\/\">UEM<\/a>\u2019s Browser Settings policy lets administrators configure, force-install, allow, restrict, and enforce specific Google Chrome extensions on managed Windows devices.<\/p>\n<p>Administrators can control Windows app deployment, monitor device <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-compliance-in-cybersecurity\/\">compliance<\/a>, and use remote actions such as Uninstall Application to remove unnecessary or unauthorized software from managed devices.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> is a monitoring real-time endpoint events and identifying anomalies such as unauthorized process execution, brute-force attempts, known malware signatures, anomalous file changes, and unauthorized network beaconing.<\/p>\n<p>Correlating XDR security alerts with UEM context, including device compliance status, user identity, and location, helps security teams prioritize vulnerability remediation.<\/p>\n<h2>Conclusion<\/h2>\n<p>Edgecution demonstrates that browser security can no longer be viewed independently from endpoint security.<\/p>\n<p>By combining Microsoft Teams phishing, malicious browser extensions, Chrome Native Messaging, and a Python backdoor, attackers transformed a legitimate browser integration feature into a bridge for host-level compromise.<\/p>\n<p>The campaign highlights how trusted enterprise technologies can be abused when users are deceived into installing malicious software.<\/p>\n<p>Organizations should strengthen browser extension security, restrict Native Messaging where possible, verify IT support workflows, monitor headless browser activity, and deploy XDR solutions capable of detecting browser-to-host attack chains before they evolve into ransomware incidents.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Block Browser-Based Ransomware Access Bridges<\/h5><p>Control extensions, detect Python backdoors, and stop browser-to-host attacks with Hexnode UEM and XDR faster.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can legitimate browser extensions use Native Messaging safely?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Native Messaging is a legitimate feature designed for trusted desktop integrations, but organizations should allow only approved extensions and native applications.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why are collaboration platforms increasingly used in phishing campaigns?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Employees naturally trust workplace communication tools, making them effective channels for impersonation, fake support requests, and malware delivery.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A newly discovered malware campaign dubbed Edgecution malware reveals how attackers can weaponize trusted browser&#8230;<\/p>\n","protected":false},"author":6,"featured_media":575,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16],"class_list":["post-573","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Edgecution Malware Abuses Edge Native Messaging<\/title>\n<meta name=\"description\" content=\"Learn how Edgecution malware abuses Edge Native Messaging to deploy a Python backdoor and how enterprises can defend browser-based attacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Edgecution Malware Abuses Edge Native Messaging\" \/>\n<meta property=\"og:description\" content=\"Learn how Edgecution malware abuses Edge Native Messaging to deploy a Python backdoor and how enterprises can defend browser-based attacks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-29T09:27:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T09:30:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Edgecution Turns Microsoft Edge Native Messaging Into a Ransomware Access Bridge\",\"datePublished\":\"2026-06-29T09:27:12+00:00\",\"dateModified\":\"2026-08-18T09:30:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/\"},\"wordCount\":832,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp\",\"articleSection\":[\"Malware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/\",\"name\":\"Edgecution Malware Abuses Edge Native Messaging\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp\",\"datePublished\":\"2026-06-29T09:27:12+00:00\",\"dateModified\":\"2026-08-18T09:30:42+00:00\",\"description\":\"Learn how Edgecution malware abuses Edge Native Messaging to deploy a Python backdoor and how enterprises can defend browser-based attacks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Edgecution Turns Microsoft Edge Native Messaging Into a Ransomware Access Bridge\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Edgecution Turns Microsoft Edge Native Messaging Into a Ransomware Access Bridge\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Edgecution Malware Abuses Edge Native Messaging","description":"Learn how Edgecution malware abuses Edge Native Messaging to deploy a Python backdoor and how enterprises can defend browser-based attacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/","og_locale":"en_US","og_type":"article","og_title":"Edgecution Malware Abuses Edge Native Messaging","og_description":"Learn how Edgecution malware abuses Edge Native Messaging to deploy a Python backdoor and how enterprises can defend browser-based attacks.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-29T09:27:12+00:00","article_modified_time":"2026-08-18T09:30:42+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Edgecution Turns Microsoft Edge Native Messaging Into a Ransomware Access Bridge","datePublished":"2026-06-29T09:27:12+00:00","dateModified":"2026-08-18T09:30:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/"},"wordCount":832,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp","articleSection":["Malware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/","url":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/","name":"Edgecution Malware Abuses Edge Native Messaging","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp","datePublished":"2026-06-29T09:27:12+00:00","dateModified":"2026-08-18T09:30:42+00:00","description":"Learn how Edgecution malware abuses Edge Native Messaging to deploy a Python backdoor and how enterprises can defend browser-based attacks.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Edgecution-Turns-Microsoft-Edge-Native-Messaging-Into-a-Ransomware-Access-Bridge.png?format=webp","width":1340,"height":700,"caption":"Edgecution Turns Microsoft Edge Native Messaging Into a Ransomware Access Bridge"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/edgecution-turns-microsoft-edge-native-messaging-into-a-ransomware-access-bridge\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Edgecution Turns Microsoft Edge Native Messaging Into a Ransomware Access Bridge"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=573"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/573\/revisions"}],"predecessor-version":[{"id":576,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/573\/revisions\/576"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/575"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}