Low signal — weak indicators present
Only weak/low-confidence indicators were found. May be benign — use context.
cmd.exe /d /s /c ""C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26050.15-0\mpextms.exe" chrome-extension://lcmcgbabdcbngcbcfabdncmoppkajglo/ --parent-window=0" < \\.\pipe\chrome.nativeMessaging.in.351126fb478d8ae8 > \\.\pipe\chrome.nativeMessaging.out.351126fb478d8ae8
Uses the Windows Command Prompt to execute an inline Windows command.
The command leverages Cmd.exe, a Windows binary catalogued in LOLBAS as commonly abused for living-off-the-land attacks — known abuse categories: ADS, Upload, and Download.
While the detected binaries have legitimate administrative uses, their presence in an investigation warrants scrutiny of process lineage, network connections made during execution, and any files created or modified.
North Korean state-sponsored group linked to the $81M Bangladesh Bank heist, WannaCry ransomware, and Sony Pictures breach. The most prolific nation-state financial threat actor.
Attribution based on MITRE ATT&CK technique overlap. Confidence reflects TTP match depth — not a definitive attribution.