A sophisticated malware campaign discovered in June 2026 is using a clever combination of legitimate technologies to compromise Windows systems.
By abusing Google Chrome policy keys and Native Messaging features, attackers are forcing the installation of a malicious browser extension.
This extension effectively transforms into a full remote-command backdoor, bypassing standard browser security boundaries.
The attack begins with a simple but effective Italian-language phishing email. The message pretends to deliver a business invoice and contains a disguised attachment named Fattura-2819889242.pfd.js.
The unusual .pfd.js ending tricks victims into glancing at the file and assuming it is a standard PDF document. When a user clicks this attachment, the Windows Script Host executes the obfuscated JavaScript.
Once executed, the script drops two files into the user’s temporary directory. The first is a legitimate, digitally signed executable named client_124578.exe associated with Epic Games.
The second is a malicious library named d3d11.dll. When the trusted Epic Games application runs, Windows automatically resolves its dependencies and loads the attacker-controlled DLL.
This technique, known as DLL side-loading, allows the malware to secretly launch a hidden PowerShell process without triggering traditional antivirus alarms.
Chrome Policies Force Extensions
The hidden PowerShell script immediately targets Chrome’s enterprise policy keys in the Windows registry.
It modifies the ExtensionInstallAllowlist and ExtensionInstallSources paths to make the malware appear as an administrator-controlled deployment.

This forces the browser to install a malicious extension named “Cloud vn105rkj64 ” silently. Normally, browser extensions are locked inside a secure sandbox and cannot run local programs on a computer.
To bypass this vital security restriction, the attackers exploit a legitimate Chrome feature called Native Messaging. Tools like password managers legally use this feature to exchange data between a browser extension and the operating system.
The malware registers a Native Messaging Host on the system, creating a direct communication bridge between the malicious Chrome extension and the local Windows environment.

With this bridge established, the Chrome extension acts as a remote controller connecting to an external command server over a standard HTTPS channel.
The extension steals active session cookies, open tabs, and browser fingerprinting information. More dangerously, the command server can send instructions directly through the extension to the Native Messaging Host.
In this campaign, attackers used this channel to execute local PowerShell commands, giving them total control over the victim’s machine, d3lab said.
Detection and Key Indicators
| Type | Indicator | Context |
|---|---|---|
| Email subject | Fattura #2818999851 | Italian invoice lure |
| Displayed filename | Fattura-26189991026.pdf | Document shown in the email |
| Payload filename | Fattura-2819889242.pfd.js | Obfuscated Windows JavaScript |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.