BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Microsoft’s Edge Store Hit by Stealthy “StegoAd” Malware

Microsoft dismantles StegoAd campaign hiding malware in images to steal credentials

  • Microsoft shut down a large-scale malicious extension campaign on its Edge Add-ons store, dubbed StegoAd, which had up to 2.6 million potential installs.
  • The campaign hid malicious code inside image and font files using steganography, delaying activation for days to evade detection while stealing credentials and committing ad fraud.
  • Users should check their installed extensions against Microsoft’s published list and change passwords, as the threat actor remains active.

In a major security crackdown, Microsoft has dismantled a massive, long-running malicious extension operation on its Edge Add-ons store, targeting millions of users with sophisticated credential theft and ad fraud. The campaign, which Microsoft calls StegoAd, cleverly hid its payloads within ordinary image and font files to avoid detection. This operation involved 119 seemingly benign extensions, such as ad blockers and VPNs, that had collectively been installed up to 2.6 million times.

- Advertisement -

The malicious code remained dormant for days after installation, only activating if it passed a series of evasion checks. Consequently, many users may have been spared the final payload despite having the extension. The attackers employed advanced steganography, embedding executable JavaScript within PNG and WebP images or even WOFF2 font files. Some variants fetched payloads dynamically from command-and-control servers, which only responded to properly fingerprinted requests.

Meanwhile, the extensions monitored for open developer tools, extending their dormancy if analysis was suspected. The visible impact was ad fraud, including injected ads and hijacked affiliate commissions on major e-commerce sites. However, Microsoft’s analysis revealed a more sinister layer, including a remote code execution backdoor and the theft of Google credentials, second-factor codes, and WordPress admin logins.

The operation’s infrastructure was robust, utilizing over ten command-and-control domains with automatic failover and abusing services like Cloudflare Workers and GitHub Pages. Microsoft has removed all 119 extensions and suspended the associated developer accounts. The company urges users to check their installed extensions against the list in its technical report and change passwords for sensitive accounts. Evidence suggests this campaign is linked to the known threat actor DarkSpectre, indicating the operator remains active.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Wells Fargo Cuts Nvidia Target But Keeps Buy Rating

Wells Fargo's Aaron Rakers reduced NVIDIA's price target from $375 to $315 but maintains...

Aave Could Outrun Bitcoin, Gain 50x By 2030: Analyst

Bitcoin has fallen over 50% from its October all-time high as a major crypto...

U.S., Ukraine Uncover Russian Cyber Spy Campaign

The Security Service of Ukraine and FBI uncovered a long-running Russian cyber-espionage campaign targeting...

Nvidia’s $1,000 IPO Investment Now Worth Multi-Millions

A $1,000 investment in NVIDIA at its 1999 IPO, adjusted for splits, would be...

Ripple processed $16T but used almost no crypto

Ripple CEO criticized Strategy's leveraged funding model for hurting the wider crypto market.Brad Garlinghouse...

Must Read

7 Best NFT Marketplaces for Every Need

Open Sea | Pianity | Foundation | Magic Eden | SuperRare | Rarible | Theta Drop | Other Platforms | About NFTs | FAQ...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading