StegoAd Campaign: 119 Malicious Microsoft Edge Extensions Deliver Steganographic Malware to 2.6M Users — Threadlinqs Intelligence
As of 2026-07-11, StegoAd Campaign: 119 Malicious Microsoft Edge Extensions Deliver Steganographic Malware to 2.6M Users is a high-severity malware threat attributed to DarkSpectre, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1207 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: DarkSpectre · FINANCIAL
Microsoft's Edge Extensions Security Team disrupted "StegoAd," a multi-year (active since at least 2021) supply-chain campaign of 119 malicious Edge browser extensions across 90+ developer accounts,
StegoAd is a long-running (since at least 2021) malicious browser-extension operation targeting the Microsoft Edge Add-ons store, disclosed and disrupted by Microsoft's Edge Extensions Security Team in June 2026 after enterprise customers reported unusual browser behavior (unexpected pop-ups, unauthorized redirects, sluggish performance) starting in early May 2026. The operation ran 119 extensions across 90+ distinct developer accounts, impersonating trusted extension categories -- ad blockers ("Ads Block Ultimate", "Adblock for Youtube", "Adblocker FX", "Adblock" as a uBlock clone), VPNs ("Trusted VPN for Edge (VeePN)", "Hiddence VPN"), translators ("Google Translate in Right Click"), video downloaders ("Free Online Video Downloader", "Turbo Download Manager", "TikTok APP for Edge"), AI tools ("AI Search GPT for Edge"), image tools ("Image Downloader Pro"), and other utility categories (color pickers, PDF editors, weather apps, bandwidth optimizers, Pomodoro timers, screenshot tools, social-media integrators, coupon tools, calculators).
The extensions delivered genuine baseline functionality to build trust and pass store review, then deployed malicious payloads three to five days post-install (a dormancy/sleeper design), with additional evasion via DevTools-detection logic (extending dormancy indefinitely if developer tools were open) and server-side request validation/fingerprint and User-Agent gating on the C2 side, so direct researcher probes returned empty responses. Execution was probabilistic -- only roughly 10% of installations ever fired the payload, limiting exposure to automated analysis and complicating detection.
The steganographic delivery chain evolved over time as Microsoft's detection improved: early variants appended JavaScript after the IEND marker of PNG icon files bundled with the extension; the operators then moved to fetching external PNGs from C2 servers, then to WebP image containers, and finally to WOFF2 web-font files with code hidden in glyph ranges disguised as Asian-language text or font metadata. Retrieved payload strings were further multi-layer obfuscated using character case-swaps, digit-swaps, Base64 encoding, and XOR. The operators successfully ported the extension codebase from Manifest V2 to Manifest V3 as Chromium deprecated the older extension platform, indicating sustained active maintenance.
Microsoft's analysis attributes at least 10 distinct malicious modules to the retrieved payloads: Google credential and second-factor (2FA) code interception at sign-in, WordPress administrator credential harvesting, bulk cookie collection/exfiltration for session hijacking, a remote-code-execution backdoor that executes arbitrary JavaScript pushed from C2, ad injection/ad fraud, affiliate-commission hijacking targeting Amazon, eBay, and AliExpress referral links, search-result redirection, and competitor-extension targeting/removal. Covert telemetry was routed through at least seven distinct Google Analytics tracking IDs, giving the operators real-time dashboards on infected populations. Command-and-control relied on 10+ domains organized by function with automatic failover, fronted in part through Cloudflare Workers, with additional beacon/telemetry traffic abused through GitHub Pages hosting. One credential-exfiltration domain identified in follow-on reporting is mitarchive[.]info, associated with a broader operation Microsoft describes as sharing infrastructure, hashing/debug-string patterns, AdSense publisher IDs, and Analytics properties across all 119 extensions despite the 90+ separate developer accounts -- consistent with a single actor rapidly recreating suspended accounts. A BeaconBeagle infrastructure-correlation check on mitarchive[.]info returned no additional C2 configuration matches at the time of this research (2026-07), indicating either fresh/rotated infrastructure or a domain not yet indexed by that source.
Security researchers (via The Hacker News and Rescana reporting) hav
Weaknesses (CWE)
CWE-506, CWE-912, CWE-522
Target sectors: all sectors consumer enterprise browser users, ecommerce, content management wordpress site operators
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1585, T1584, T1566, T1195, T1189, T1059, T1204, T1176, T1027, T1027