Microsoft Disrupts StegoAd Campaign with Malicious Edge Extensions

Microsoft Disrupts StegoAd Campaign with Malicious Edge Extensions

First seen 29 Jun 2026, 12:55 UTC News.Risky.BizTechnaduFeeds.4SysopsRedmondmagFeeds.Feedburner 85% similarity 69.0
Share:

Article Content

Browse articles
ThreatCluster

Microsoft has dismantled the StegoAd operation, removing 119 malicious Edge extensions that used steganography to hide malware within image and font files. The campaign, active since 2021, targeted over 2.6 million users, employing techniques like remote code execution and time-delayed payload activation. The extensions masqueraded as legitimate tools, including ad blockers and VPNs, while executing credential theft and ad fraud. Microsoft confirmed that the threat actors demonstrated advanced evasion techniques, including fingerprint checks for payload delivery. The takedown highlights the ongoing risks associated with browser extensions that request access to user data. Users are advised to review their installed extensions and change passwords if affected. The full list of malicious extensions is available in a detailed report by Microsoft.

Key Points: • Microsoft removed 119 malicious Edge extensions involved in the StegoAd campaign. • The operation utilized steganography to conceal malware within image and font files. • Over 2.6 million users may have been affected by these malicious extensions.

ThreatCluster AI

Timeline

2021-01-01
StegoAd operation began
The threat actor behind StegoAd has been active since at least 2021, developing malicious extensions.
News.Risky.Biz
2026-06-18
CVE-2026-12569 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-29
Microsoft removes malicious extensions
Microsoft dismantled the StegoAd campaign, removing 119 extensions from the Edge Add-ons store.
Technadu
2026-06-29
Malware delivery method revealed
The extensions used steganography to hide malicious payloads in image and font files, remaining dormant initially.
Feeds.Feedburner
2026-06-29
Scope of impact confirmed
The campaign is believed to have affected over 2.6 million users, with techniques for credential theft and ad fraud.
Feeds.4Sysops

Community

Browse all →