BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft’s Edge Store Hit by Stealthy “StegoAd” Malware

Microsoft dismantles StegoAd campaign hiding malware in images to steal credentials

  • Microsoft shut down a large-scale malicious extension campaign on its Edge Add-ons store, dubbed StegoAd, which had up to 2.6 million potential installs.
  • The campaign hid malicious code inside image and font files using steganography, delaying activation for days to evade detection while stealing credentials and committing ad fraud.
  • Users should check their installed extensions against Microsoft’s published list and change passwords, as the threat actor remains active.

In a major security crackdown, Microsoft has dismantled a massive, long-running malicious extension operation on its Edge Add-ons store, targeting millions of users with sophisticated credential theft and ad fraud. The campaign, which Microsoft calls StegoAd, cleverly hid its payloads within ordinary image and font files to avoid detection. This operation involved 119 seemingly benign extensions, such as ad blockers and VPNs, that had collectively been installed up to 2.6 million times.

- Advertisement -

The malicious code remained dormant for days after installation, only activating if it passed a series of evasion checks. Consequently, many users may have been spared the final payload despite having the extension. The attackers employed advanced steganography, embedding executable JavaScript within PNG and WebP images or even WOFF2 font files. Some variants fetched payloads dynamically from command-and-control servers, which only responded to properly fingerprinted requests.

Meanwhile, the extensions monitored for open developer tools, extending their dormancy if analysis was suspected. The visible impact was ad fraud, including injected ads and hijacked affiliate commissions on major e-commerce sites. However, Microsoft’s analysis revealed a more sinister layer, including a remote code execution backdoor and the theft of Google credentials, second-factor codes, and WordPress admin logins.

The operation’s infrastructure was robust, utilizing over ten command-and-control domains with automatic failover and abusing services like Cloudflare Workers and GitHub Pages. Microsoft has removed all 119 extensions and suspended the associated developer accounts. The company urges users to check their installed extensions against the list in its technical report and change passwords for sensitive accounts. Evidence suggests this campaign is linked to the known threat actor DarkSpectre, indicating the operator remains active.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coinbase launches UK derivatives with up to 50x leverage

Coinbase is launching futures, perpetuals, and options for professional investors in the UK, with...

South Korea expands crypto Travel Rule to all transfers

South Korea will eliminate the $700 threshold for crypto Travel Rule compliance, applying it...

Strategy sells 1,690 Bitcoin for $108.6 million

Strategy sold 1,690 Bitcoin for roughly $108.6 million last week, marking its second sale...

Trump Media Revamps Digital Asset Strategy After $238M Loss

Trump Media reported a $238 million net loss in Q2, largely due to $190.4...

Buterin: Ethereum’s New Roadmap Boosts Quantum Security, AI

Ethereum co-founder Vitalik Buterin says quantum resistance, privacy, and AI-assisted security have become greater...

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading