Malicious 'PDF Viewer' extension with combined cookie+clipboard permissions
Detects the malicious 'PDF Viewer' extension (bridged via the com.microsoft.runedge native-messaging helper) requesting both cookie-access and clipboard-access permissions together — the specific combination Jewelbug uses for session-token theft and cryptocurrency address swapping.
Microsoft Sentinel (KQL)

