logo

Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts

ID: 342370b1-cff1-587e-b6be-7c6985373b4c

STIX ID: report--342370b1-cff1-587e-b6be-7c6985373b4c

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-06-29

Date Updated: 2026-07-01

Author: [email protected] (The Hacker News)

...
...

Microsoft dismantled a long-running malicious extension campaign called "StegoAd" that hid JavaScript payloads inside images and WOFF2 fonts to evade detection; 119 Edge extensions tied to a single operator were removed, with a combined install base up to 2.6 million. The extensions performed ad fraud and stole credentials, 2FA codes, WordPress admin logins and cookies, delivered a remote code execution backdoor, and used resilient C2 infrastructure and evasion checks (delays, fingerprinting, Cloudflare Workers, GitHub Pages). Microsoft published indicators of compromise and recommends users compare installed extensions to the removal list, change sensitive passwords, review sign-ins, and enable strong two-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.