StegoAd Campaign: 119 Malicious Edge Extensions Hid Malware in Images, Fonts, and Config Files, Up to 2.6M Installs — Threadlinqs Intelligence
As of 2026-07-11, StegoAd Campaign: 119 Malicious Edge Extensions Hid Malware in Images, Fonts, and Config Files, Up to 2.6M Installs is a high-severity malware threat attributed to DarkSpectre (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1221 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: DarkSpectre · China · FINANCIAL
Microsoft's Edge Security Team disrupted StegoAd, a threat actor operating since at least 2021 across 90+ developer accounts and 119 Microsoft Edge extensions (ad blockers, VPNs, translators, video
StegoAd is a long-running (2021–2026), financially motivated browser-extension supply-chain campaign that Microsoft's Edge Extensions Security Team disrupted in June 2026 by removing 119 malicious Edge Add-ons and suspending more than 90 associated developer accounts. The extensions impersonated everyday utilities — ad blockers, VPNs, translators, video downloaders, shopping helpers, and color tools — that functioned correctly and accumulated genuine user reviews, allowing them to persist in the Edge Add-ons store for years while quietly amassing an installed base Microsoft caps at up to 2.6 million (explicitly described as a ceiling, not a confirmed-victim count).
The defining tradecraft of the campaign is a four-generation steganographic evolution used to smuggle a JavaScript backdoor past static and dynamic store-review scanning: (1) the earliest variants appended raw JavaScript after the IEND marker of a PNG icon so the image rendered normally everywhere while carrying an invisible payload; (2) as detection improved, the actor shifted to fetching an external PNG from C2 infrastructure with an encoded payload; (3) next, WebP image containers were used with the same append/encode methodology; (4) the actor then moved to WOFF2 web-font files, hiding payload bytes as high-Unicode codepoints in glyph ranges that visually resemble Asian-language text or font metadata; and (5) a March 2026 variant abandoned media steganography for a disguised configuration file (`setting.conf`) containing Base64 payload segments delimited by `/////` sentinels. Across all generations, payload material passes through multiple decode layers — case-swap and digit-swap obfuscation, Base64, XOR, and double-Base64 for exfiltrated data — before execution.
Approximately 66 of the 119 extensions share a common polymorphic delivery framework the actor's own code refers to internally as "orderArray," deployed under 15+ naming variants and composed of an encoded payload object, a seed generator, a regex-based decoder, and a double-Base64 extraction routine. The backdoor delivers roughly 10 distinct payload modules once activated, including credential theft (Google account sign-in interception of both password and second-factor codes, and WordPress administrator login harvesting with pages tagged via SimilarWeb rank data to prioritize high-value targets for double-Base64 exfiltration), bulk session-cookie collection for session hijacking, affiliate-commission hijacking across 20+ Amazon country storefronts plus eBay, AliExpress, Taobao, and JD.com, ad injection/replacement capped at six slots per page across Google AdSense and Amazon ad units, search-result redirection, and a general-purpose remote-code-execution channel that fetches and executes arbitrary JavaScript from C2 within roughly 10 milliseconds of a fingerprint-validated request.
Activation is heavily gated to frustrate analysis and limit mass compromise: extensions enforce a 3–5.5 day post-install dormancy window before any payload logic runs, some variants only activate in roughly 10% of sessions (probabilistic execution gating), and a DevTools-open detection flag (`dipFlgDev`) extends dormancy indefinitely if a user or analyst has developer tools open. C2 servers additionally validate the requesting extension's runtime ID and User-Agent string before serving payload material, returning decoy/benign responses to any probe that fails fingerprint checks.
Command-and-control relies on 10+ domains with automatic failover, fronted and proxied through Cloudflare Workers, with beacon/telemetry hosting abused via GitHub Pages and seven Google Analytics (GA4) tracking IDs used as covert operational dashboards. One credential-exfiltration domain, `mitarchive.info`, was publicly attributed by security firm Koi Security to a Chinese-linked actor it tracks as DarkSpectre, based on Alibaba Cloud-hosted C2 infrastructure, ICP domain registrations tied to Hubei Province, Chinese-language code comments, and fr
Weaknesses (CWE)
CWE-506, CWE-912, CWE-522, CWE-311, CWE-1021
Target sectors: technology, ecommerce, retail, general consumer, mediapublishing
Target regions: Global, North America, Europe, Asia Pacific, china
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1195.002, T1189, T1176, T1204.002, T1176, T1505.003, T1027, T1027.003, T1027.013, T1497.001