Threat reportMalwareTL-2026-1207
StegoAd Campaign: 119 Malicious Microsoft Edge Extensions Deliver Steganographic Malware to 2.6M Users
StegoAd Campaign (TL-2026-1207), also tracked as StegoAd, is a high-severity malware campaign, first published 2026-07-11. It is attributed to DarkSpectre with low confidence, affects Microsoft Microsoft Edge Add-ons Store (browser extensions), maps to 27 MITRE ATT&CK techniques (T1005, T1008, T1027), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 27MITRE ATT&CK
- Actors
- 1DarkSpectre
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-1207
- Threat ID
- TL-2026-1207
- Also known as
- StegoAd
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- DarkSpectre
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- all sectors consumer enterprise browser users, ecommerce, content management wordpress site operators
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in StegoAd Campaign
Malware and tooling: StegoAd
How StegoAd Campaign works
Microsoft's Edge Extensions Security Team disrupted "StegoAd," a multi-year (active since at least 2021) supply-chain campaign of 119 malicious Edge browser extensions across 90+ developer accounts, downloaded up to 2.6 million times. Extensions posed as ad blockers, VPNs, translators, video downloaders, and other utilities; hid payloads inside PNG/WebP images and WOFF2 font glyph data (steganography); remained dormant 3-5 days after install with DevTools-detection and server-side validation gates; and activated in roughly 10% of installations to run ad fraud, execute arbitrary remote JavaScript, steal Google credentials and 2FA codes, harvest WordPress admin logins, hijack affiliate commissions, and exfiltrate cookies for session hijacking.
StegoAd is a long-running (since at least 2021) malicious browser-extension operation targeting the Microsoft Edge Add-ons store, disclosed and disrupted by Microsoft's Edge Extensions Security Team in June 2026 after enterprise customers reported unusual browser behavior (unexpected pop-ups, unauthorized redirects, sluggish performance) starting in early May 2026. The operation ran 119 extensions across 90+ distinct developer accounts, impersonating trusted extension categories -- ad blockers ("Ads Block Ultimate", "Adblock for Youtube", "Adblocker FX", "Adblock" as a uBlock clone), VPNs ("Trusted VPN for Edge (VeePN)", "Hiddence VPN"), translators ("Google Translate in Right Click"), video downloaders ("Free Online Video Downloader", "Turbo Download Manager", "TikTok APP for Edge"), AI tools ("AI Search GPT for Edge"), image tools ("Image Downloader Pro"), and other utility categories (color pickers, PDF editors, weather apps, bandwidth optimizers, Pomodoro timers, screenshot tools, social-media integrators, coupon tools, calculators).
The extensions delivered genuine baseline functionality to build trust and pass store review, then deployed malicious payloads three to five days post-install (a dormancy/sleeper design), with additional evasion via DevTools-detection logic (extending dormancy indefinitely if developer tools were open) and server-side request validation/fingerprint and User-Agent gating on the C2 side, so direct researcher probes returned empty responses. Execution was probabilistic -- only roughly 10% of installations ever fired the payload, limiting exposure to automated analysis and complicating detection.
The steganographic delivery chain evolved over time as Microsoft's detection improved: early variants appended JavaScript after the IEND marker of PNG icon files bundled with the extension; the operators then moved to fetching external PNGs from C2 servers, then to WebP image containers, and finally to WOFF2 web-font files with code hidden in glyph ranges disguised as Asian-language text or font metadata. Retrieved payload strings were further multi-layer obfuscated using character case-swaps, digit-swaps, Base64 encoding, and XOR. The operators successfully ported the extension codebase from Manifest V2 to Manifest V3 as Chromium deprecated the older extension platform, indicating sustained active maintenance.
Microsoft's analysis attributes at least 10 distinct malicious modules to the retrieved payloads: Google credential and second-factor (2FA) code interception at sign-in, WordPress administrator credential harvesting, bulk cookie collection/exfiltration for session hijacking, a remote-code-execution backdoor that executes arbitrary JavaScript pushed from C2, ad injection/ad fraud, affiliate-commission hijacking targeting Amazon, eBay, and AliExpress referral links, search-result redirection, and competitor-extension targeting/removal. Covert telemetry was routed through at least seven distinct Google Analytics tracking IDs, giving the operators real-time dashboards on infected populations. Command-and-control relied on 10+ domains organized by function with automatic failover, fronted in part through Cloudflare Workers, with additional beacon/telemetry traffic abused through GitHub Pages hosting. One credential-exfiltration domain identified in follow-on reporting is mitarchive[.]info, associated with a broader operation Microsoft describes as sharing infrastructure, hashing/debug-string patterns, AdSense publisher IDs, and Analytics properties across all 119 extensions despite the 90+ separate developer accounts -- consistent with a single actor rapidly recreating suspended accounts. A BeaconBeagle infrastructure-correlation check on mitarchive[.]info returned no additional C2 configuration matches at the time of this research (2026-07), indicating either fresh/rotated infrastructure or a domain not yet indexed by that source.
Security researchers (via The Hacker News and Rescana reporting) have flagged methodological overlap -- identical icon-based steganography, overlapping extension naming conventions (e.g. "Ads Block Ultimate"), and shared credential-exfiltration infrastructure -- with a cluster tracked as DarkSpectre, and noted similarity to prior campaigns dubbed ShadyPanda and GhostPoster. Microsoft has not officially confirmed attribution to any named actor or nation-state as of the June 2026 disclosure. No CVE applies; this is an abuse-of-platform / malicious-extension supply-chain campaign rather than a software vulnerability. Microsoft removed all 119 extensions from the Edge Add-ons store, suspended 90+ developer accounts, published extension-ID indicators for user self-check (edge://extensions), and deployed dynamic C2-response analysis plus steganographic content scanning for future store submissions. Reporting notes the malicious codebase also produced Chrome- and Firefox-targeted variants, so remediation guidance extends beyond Edge, and the operator is assessed to remain active post-disruption.
MITRE ATT&CK techniques used in TL-2026-1207
Collection
T1005 Data from Local System; T1119 Automated Collection; T1185 Browser Session Hijacking
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Persistence
Initial Access
T1189 Drive-by Compromise; T1195 Supply Chain Compromise; T1566 Phishing
Discovery
Resource Development
T1584 Compromise Infrastructure; T1585 Establish Accounts
Impact
Affected products and versions in StegoAd Campaign
- Microsoft — Microsoft Edge Add-ons Store (browser extensions)
Vulnerable versions: Manifest V2 extensions; Manifest V3 extensions
Fixed in: All 119 identified extensions removed from store as of 2026-06-16 - Various (impersonated third-party developers) — Chromium-based / Chrome and Firefox variants of the same extension codebase
Vulnerable versions: Not fully enumerated; reporting indicates cross-browser variants exist
Fixed in: Not confirmed removed on Chrome/Firefox stores as of this research
Remediation for StegoAd Campaign
Immediate actions
- Check installed Edge extensions against Microsoft's published StegoAd extension-ID list via edge://extensions and remove any matches
- Block network egress to known StegoAd C2/exfil domains, including mitarchive[.]info
- Force password resets for Google and WordPress admin accounts on any endpoint that had a matching extension installed
- Invalidate/rotate active browser session cookies for affected users to neutralize stolen-cookie session hijacking
- Audit ad-network and affiliate-program accounts (Amazon, eBay, AliExpress) for unauthorized commission redirection
Workarounds
- Disable/remove extensions matching the affected category+name patterns (ad blockers, VPNs, translators, video downloaders) sourced from unverified developer accounts until vetted
Longer-term hardening
- Deploy enterprise browser-extension allowlisting/management policies restricting installs to vetted publishers
- Enable hardware security keys / phishing-resistant MFA for Google and WordPress admin accounts
- Monitor for extension code fetching external images/fonts at runtime and flag post-install network calls to newly-registered domains as anomalous
- Extend monitoring to Chrome and Firefox, since reporting indicates the same codebase produced variants for those browsers
Weaknesses (CWE) in StegoAd Campaign
Timeline of StegoAd Campaign
- StegoAd operation assessed to begin (extensions active since at least 2021, initially built on Manifest V2 with JavaScript appended after the PNG IEND marker)
- Over more than two years of sustained activity, the operator iteratively adjusts payload encryption, rotates C2 infrastructure, migrates the extension codebase from Manifest V2 to Manifest V3, and progressively shifts steganographic carriers from PNG to WebP images and finally to WOFF2 font-glyph data as Microsoft's detection capability improves (exact per-shift dates not disclosed by Microsoft)
- Koi Security publicly links the mitarchive[.]info credential-theft domain to the DarkSpectre actor cluster, connecting it to the earlier ShadyPanda and GhostPoster malicious-extension campaigns
- Microsoft's Edge Extensions Security Team begins investigating suspicious extensions after enterprise customer reports of unexpected pop-ups, unauthorized redirects, and sluggish browser performance
- Microsoft confirms it has disabled and removed all 119 identified malicious extensions, suspended 90+ developer accounts, and publishes technical report 'Inside StegoAd'
- Malwarebytes and The Hacker News publish coverage of the StegoAd disruption, summarizing scale, payload capabilities, and evasion techniques; The Hacker News reporting surfaces the December 2025 Koi Security/DarkSpectre attribution linkage
- Follow-on reporting (Rescana, Risky Business, TechRadar, TechTimes) publishes MITRE ATT&CK mappings, the mitarchive[.]info credential-exfiltration domain, and notes possible overlap with the DarkSpectre actor cluster
- Threadlinqs Intelligence research and IOC correlation performed for this record; BeaconBeagle check on mitarchive[.]info returned no additional infrastructure matches
Sources cited for StegoAd Campaign
- 119 Edge extensions promised useful tools, instead downloaded malware
- Inside StegoAd: How We Disrupted a Massive Malicious Extension Campaign
- Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
- Microsoft dismantles StegoAd campaign using malicious Edge extensions
- Risky Bulletin: Microsoft disrupts StegoAd operation
- Active Exploitation Alert: Microsoft Edge Hit by StegoAd Malware via 119 Malicious Extensions Affecting Over 2.6 Million Users
- Microsoft Pulls 119 Malicious Edge Extensions Hiding Malware in Images
- 119 Edge extensions hid malware in images and fonts
- Microsoft takes down over 100 malicious Edge extensions hiding malware in images and fonts
- StegoAd: Microsoft Removes 119 Malicious Edge Extensions Hiding Malware in Files
- Microsoft Purges 119 Edge Extensions in StegoAd Takedown
- Microsoft Removes 119 Edge Extensions Tied to StegoAd Malware Campaign
- Microsoft Edge Security StegoAd technical report (PDF)
Detection coverage for TL-2026-1207
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1207 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.