Microsoft has removed 119 malicious extensions from the official Edge Add-ons store and suspended more than 90 developer accounts linked to a coordinated operation it calls StegoAd. The campaign, active since at least 2021, used browser add-ons that initially appeared legitimate before delivering malicious payloads three to five days after installation. Microsoft said the operation also extended to Chrome and Firefox, adapted successfully from Manifest V2 to Manifest V3, and may have reached as many as 2.6 million installs.
The actor hid malicious JavaScript inside PNG, WebP, and WOFF2 files using steganography, while relying on dormancy, fingerprinting, DevTools detection, selective payload delivery, and resilient infrastructure to evade scrutiny. Retrieved payloads enabled arbitrary JavaScript execution, theft of Google credentials and second-factor codes, harvesting of WordPress admin logins, bulk cookie exfiltration for session hijacking, and advertising/search affiliate fraud. Microsoft also identified more than 10 command-and-control domains, failover mechanisms, and supporting infrastructure that included Cloudflare Workers, GitHub Pages, and covert telemetry through Google Analytics tracking IDs, and advised affected users to treat their browsers as exposed and rotate sensitive credentials.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Security Affairs reported that Koi Security linked the credential-exfiltration domain mitarchive.info used in the StegoAd campaign to the Chinese operation DarkSpectre, previously associated with ShadyPanda and GhostPoster. This introduced a new attribution detail beyond Microsoft's original disclosure.
Microsoft publicly described StegoAd as a sophisticated operation that used steganography, dormancy, fingerprinting, and selective payload delivery to evade detection. It said the extensions may have reached up to 2.6 million installs and advised affected users to treat their browsers as exposed and rotate sensitive credentials.
Microsoft identified a coordinated campaign it calls StegoAd and removed 119 malicious extensions from the official Edge Add-ons store. The company also linked more than 90 developer accounts to the operation and suspended those accounts.
Microsoft said the threat actor behind the StegoAd operation has been active since at least 2021, running a coordinated malicious browser extension campaign across browser ecosystems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcescworld.com
Open sourcemalwarebytes.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcenews.risky.biz
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.