Edgecution
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
1 technique
Initial Access
Execution
8 techniques
Execution
the commands will configure the environment, fix the encrypted ZIP file headers, extract relevant files, and create a scheduled task that executes Microsoft Edge.
OS Version Verification Copies a PowerShell script to the clipboard that is used to set up and deploy the Edgecution malware.
Outlook Version Verification Copies a Windows batch script to the clipboard that is used to set up and deploy the Edgecution malware.
the native directory contains a single obfuscated Python script... the Python backdoor can directly access the victim’s filesystem, execute arbitrary commands, create processes, etc.
the Edgecution browser extension uses the Chrome native messaging protocol to invoke a Python backdoor that can directly access the victim’s filesystem, execute arbitrary commands, create processes, etc.
Persistence
3 techniques
Persistence
the commands will configure the environment, fix the encrypted ZIP file headers, extract relevant files, and create a scheduled task that executes Microsoft Edge.
Privilege Escalation
1 technique
Privilege Escalation
Stealth
3 techniques
Stealth
Downloads an obfuscated AutoHotKey script... Downloads an encrypted ZIP file (with the PK magic bytes removed)... used to decrypt the strings in the Python backdoor.
Defense Impairment
1 technique
Defense Impairment
Credential Access
1 technique
Credential Access
Discovery
3 techniques
Discovery
Collection
1 technique
Collection
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious Microsoft Edge extension paired with a Python-based backdoor that abuses Chrome native messaging to escape the browser sandbox, communicate with C2 over WebSockets, collect system information, access the filesystem, execute shell/PowerShell/Python code, and launch processes for host compromise.
A malware framework consisting of a malicious Microsoft Edge browser extension and a Python backdoor. It is deployed via social engineering, runs Edge in headless mode, communicates with C2 over WebSockets, and uses Chrome native messaging to escape the browser sandbox and execute commands, access the filesystem, run PowerShell/Python code, write files, and enumerate processes.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.