typetechniqueconfidencemediumcreated2026-08-07updated2026-08-07evasiondefense-evasionmasqueradepe-export-table

chromium-edge-elf-export-masquerade

Malware masquerades as a legitimate Microsoft Edge / Chromium component DLL by embedding real Edge ELF (Early Launch Anti-Malware), Crashpad, and PWA Helper export names into its own PE export table. The legitimate names provide credibility during superficial triage while the actual payload is hidden elsewhere (runtime-decrypted, companion-file, or embedded in a different section).

Observed Manifestation

Sample 9a69ad1b (2.5 MB .NET 9 Native AOT DLL) includes exports such as:

  • SignalChromeElf
  • EdgeGetElfCommandLine
  • GetCrashpadDatabasePath_ExportThunk
  • InjectDumpForHungInput_ExportThunk
  • Full edge_pwahelper::PwaHelperImpl vtable with methods like BadgeNotification, DigitalGoodsConsume, PinTileToTaskbar, ValidateHandShake, InitMojo

All resolve to stubs; the DLL is not a browser component. ^[raw/analyses/9a69ad1b.../report.md]

Related