EchoGram Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 21, 2025
Last Seen
November 21, 2025

EchoGram is a malware family linked to campaigns within the Hidden Comet ecosystem.

Overview

EchoGram is a malware family linked to campaigns within the Hidden Comet ecosystem. A recent report highlights the Hidden Comet Browser API as capable of enabling dangerous local command execution, suggesting EchoGram could leverage browser contexts to issue commands on infected hosts. This signals a shift toward browser-assisted execution techniques that expand EchoGram's potential stealth and reach in compromised environments.

Related Threat Clusters

  • Comet AI Browser API Allows Unauthorized Device Control

    SquareX researchers have identified a hidden MCP API in the Comet AI browser that enables embedded extensions to execute local commands and potentially take full control of users' devices. This API circumvents…

    6 articles · Updated November 21, 2025

Recent Intelligence Reports

  • Hidden Comet Browser API Allowed Dangerous Local Command Execution — Esecurityplanet · November 21, 2025

CVSS v3.1 Breakdown