# StegoAd Campaign: 119 Malicious Microsoft Edge Extensions Deliver Steganographic Malware to 2.6M Users

> Microsoft's Edge Extensions Security Team disrupted "StegoAd," a multi-year (active since at least 2021) supply-chain campaign of 119 malicious Edge browser extensions across 90+ developer accounts, downloaded up to 2.6 million times. Extensions posed as ad blockers, VPNs, translators, video downloaders, and other utilities; hid payloads inside PNG/WebP images and WOFF2 font glyph data (steganography); remained dormant 3-5 days after install with DevTools-detection and server-side validation gates; and activated in roughly 10% of installations to run ad fraud, execute arbitrary remote JavaScript, steal Google credentials and 2FA codes, harvest WordPress admin logins, hijack affiliate commissions, and exfiltrate cookies for session hijacking.

- **Published:** 2026-07-11T00:00:00Z
- **Last reviewed:** 2026-07-11T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1207
- **ID:** TL-2026-1207
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** DarkSpectre
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

StegoAd is a long-running (since at least 2021) malicious browser-extension operation targeting the Microsoft Edge Add-ons store, disclosed and disrupted by Microsoft's Edge Extensions Security Team in June 2026 after enterprise customers reported unusual browser behavior (unexpected pop-ups, unauthorized redirects, sluggish performance) starting in early May 2026. The operation ran 119 extensions across 90+ distinct developer accounts, impersonating trusted extension categories -- ad blockers ("Ads Block Ultimate", "Adblock for Youtube", "Adblocker FX", "Adblock" as a uBlock clone), VPNs ("Trusted VPN for Edge (VeePN)", "Hiddence VPN"), translators ("Google Translate in Right Click"), video downloaders ("Free Online Video Downloader", "Turbo Download Manager", "TikTok APP for Edge"), AI tools ("AI Search GPT for Edge"), image tools ("Image Downloader Pro"), and other utility categories (color pickers, PDF editors, weather apps, bandwidth optimizers, Pomodoro timers, screenshot tools, social-media integrators, coupon tools, calculators).

The extensions delivered genuine baseline functionality to build trust and pass store review, then deployed malicious payloads three to five days post-install (a dormancy/sleeper design), with additional evasion via DevTools-detection logic (extending dormancy indefinitely if developer tools were open) and server-side request validation/fingerprint and User-Agent gating on the C2 side, so direct researcher probes returned empty responses. Execution was probabilistic -- only roughly 10% of installations ever fired the payload, limiting exposure to automated analysis and complicating detection.

The steganographic delivery chain evolved over time as Microsoft's detection improved: early variants appended JavaScript after the IEND marker of PNG icon files bundled with the extension; the operators then moved to fetching external PNGs from C2 servers, then to WebP image containers, and finally to WOFF2 web-font files with code hidden in glyph ranges disguised as Asian-language text or font metadata. Retrieved payload strings were further multi-layer obfuscated using character case-swaps, digit-swaps, Base64 encoding, and XOR. The operators successfully ported the extension codebase from Manifest V2 to Manifest V3 as Chromium deprecated the older extension platform, indicating sustained active maintenance.

Microsoft's analysis attributes at least 10 distinct malicious modules to the retrieved payloads: Google credential and second-factor (2FA) code interception at sign-in, WordPress administrator credential harvesting, bulk cookie collection/exfiltration for session hijacking, a remote-code-execution backdoor that executes arbitrary JavaScript pushed from C2, ad injection/ad fraud, affiliate-commission hijacking targeting Amazon, eBay, and AliExpress referral links, search-result redirection, and competitor-extension targeting/removal. Covert telemetry was routed through at least seven distinct Google Analytics tracking IDs, giving the operators real-time dashboards on infected populations. Command-and-control relied on 10+ domains organized by function with automatic failover, fronted in part through Cloudflare Workers, with additional beacon/telemetry traffic abused through GitHub Pages hosting. One credential-exfiltration domain identified in follow-on reporting is mitarchive[.]info, associated with a broader operation Microsoft describes as sharing infrastructure, hashing/debug-string patterns, AdSense publisher IDs, and Analytics properties across all 119 extensions despite the 90+ separate developer accounts -- consistent with a single actor rapidly recreating suspended accounts. A BeaconBeagle infrastructure-correlation check on mitarchive[.]info returned no additional C2 configuration matches at the time of this research (2026-07), indicating either fresh/rotated infrastructure or a domain not yet indexed by that source.

Security researchers (via The Hacker News and Rescana reporting) have flagged methodological overlap -- identical icon-based steganography, overlapping extension naming conventions (e.g. "Ads Block Ultimate"), and shared credential-exfiltration infrastructure -- with a cluster tracked as DarkSpectre, and noted similarity to prior campaigns dubbed ShadyPanda and GhostPoster. Microsoft has not officially confirmed attribution to any named actor or nation-state as of the June 2026 disclosure. No CVE applies; this is an abuse-of-platform / malicious-extension supply-chain campaign rather than a software vulnerability. Microsoft removed all 119 extensions from the Edge Add-ons store, suspended 90+ developer accounts, published extension-ID indicators for user self-check (edge://extensions), and deployed dynamic C2-response analysis plus steganographic content scanning for future store submissions. Reporting notes the malicious codebase also produced Chrome- and Firefox-targeted variants, so remediation guidance extends beyond Edge, and the operator is assessed to remain active post-disruption.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1584 Compromise Infrastructure
- T1566 Phishing
- T1195 Supply Chain Compromise
- T1189 Drive-by Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1176 Software Extensions
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1036 Masquerading
- T1070 Indicator Removal
- T1539 Steal Web Session Cookie
- T1555 Credentials from Password Stores
- T1111 Multi-Factor Authentication Interception
- T1056 Input Capture
- T1119 Automated Collection
- T1005 Data from Local System
- T1185 Browser Session Hijacking
- T1071 Application Layer Protocol
- T1102 Web Service
- T1090 Proxy
- T1105 Ingress Tool Transfer
- T1008 Fallback Channels
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft
- T1518 Software Discovery

## Sources

- [119 Edge extensions promised useful tools, instead downloaded malware](https://www.malwarebytes.com/blog/news/2026/06/119-edge-extensions-promised-useful-tools-instead-downloaded-malware)
- [Inside StegoAd: How We Disrupted a Massive Malicious Extension Campaign](https://microsoftedge.github.io/edgevr/posts/Inside-StegoAd-How-We-Disrupted-a-Massive-Malicious-Extension-Campaign/)
- [Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts](https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html)
- [Microsoft dismantles StegoAd campaign using malicious Edge extensions](https://www.scworld.com/brief/microsoft-dismantles-stegoad-campaign-using-malicious-edge-extensions)
- [Risky Bulletin: Microsoft disrupts StegoAd operation](https://news.risky.biz/risky-bulletin-microsoft-disrupts-stegoad-operation/)
- [Active Exploitation Alert: Microsoft Edge Hit by StegoAd Malware via 119 Malicious Extensions Affecting Over 2.6 Million Users](https://www.rescana.com/post/active-exploitation-alert-microsoft-edge-hit-by-stegoad-malware-via-119-malicious-extensions-affecting-over-2-6-million)
- [Microsoft Pulls 119 Malicious Edge Extensions Hiding Malware in Images](https://www.techtimes.com/articles/319365/20260630/microsoft-pulls-119-malicious-edge-extensions-hiding-malware-images.htm)
- [119 Edge extensions hid malware in images and fonts](https://hackmag.com/news/stegoad)
- [Microsoft takes down over 100 malicious Edge extensions hiding malware in images and fonts](https://www.techradar.com/pro/security/microsoft-takes-down-over-100-malicious-edge-extensions-hiding-malware-in-images-and-fonts)
- [StegoAd: Microsoft Removes 119 Malicious Edge Extensions Hiding Malware in Files](https://windowsforum.com/threads/stegoad-microsoft-removes-119-malicious-edge-extensions-hiding-malware-in-files.432033/)
- [Microsoft Purges 119 Edge Extensions in StegoAd Takedown](https://windowsnews.ai/article/microsoft-purges-119-edge-extensions-in-stegoad-takedown-the-steganography-malware-campaign-exposed.432033)
- [Microsoft Removes 119 Edge Extensions Tied to StegoAd Malware Campaign](https://www.mallory.ai/stories/019f1124-b58b-75e8-a741-c43cfa48055c)
- [Microsoft Edge Security StegoAd technical report (PDF)](https://microsoftedge.github.io/edgevr/assets/files/stego_ad/Microsoft_Edge_Security_StegoAd.pdf)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1207
