chromium-edge-elf-export-masquerade
Malware masquerades as a legitimate Microsoft Edge / Chromium component DLL by embedding real Edge ELF (Early Launch Anti-Malware), Crashpad, and PWA Helper export names into its own PE export table. The legitimate names provide credibility during superficial triage while the actual payload is hidden elsewhere (runtime-decrypted, companion-file, or embedded in a different section).
Observed Manifestation
Sample 9a69ad1b (2.5 MB .NET 9 Native AOT DLL) includes exports such as:
SignalChromeElfEdgeGetElfCommandLineGetCrashpadDatabasePath_ExportThunkInjectDumpForHungInput_ExportThunk- Full
edge_pwahelper::PwaHelperImplvtable with methods likeBadgeNotification,DigitalGoodsConsume,PinTileToTaskbar,ValidateHandShake,InitMojo
All resolve to stubs; the DLL is not a browser component. ^[raw/analyses/9a69ad1b.../report.md]
Related
- semantic-jargon-export-obfuscation — the broader technique of mixing real and noise export names
- version-info-masquerade — frequently paired with export-table masquerade
- unclassified-dotnet-native-aot-loader — family where this was first observed