Threat reportMalwareTL-2026-1221
StegoAd Campaign: 119 Malicious Edge Extensions Hid Malware in Images, Fonts, and Config Files, Up to 2.6M Installs
StegoAd Campaign (TL-2026-1221), also tracked as StegoAd, is a high-severity malware campaign, first published 2026-07-11. It is attributed to DarkSpectre (China) with medium confidence, affects Microsoft Microsoft Edge Add-ons Store / Extensions, maps to 33 MITRE ATT&CK techniques (T1001.002, T1005, T1008), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 33MITRE ATT&CK
- Actors
- 1DarkSpectre
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1221
- Threat ID
- TL-2026-1221
- Also known as
- StegoAd
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- DarkSpectre
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- technology, ecommerce, retail, general consumer, mediapublishing
- Target regions
- Global, North America, Europe, Asia Pacific, china
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in StegoAd Campaign
Malware and tooling: StegoAd, orderArray
How StegoAd Campaign works
Microsoft's Edge Security Team disrupted StegoAd, a threat actor operating since at least 2021 across 90+ developer accounts and 119 Microsoft Edge extensions (ad blockers, VPNs, translators, video downloaders, shopping helpers) with a combined install base of up to 2.6 million. The extensions used a four-generation steganography evolution — JavaScript appended after PNG IEND markers, external PNG payloads, WebP containers, WOFF2 font glyph ranges, and finally Base64 'setting.conf' files — to smuggle a polymorphic backdoor ("orderArray" framework) that stole Google/WordPress credentials and session cookies, hijacked affiliate links, injected ads, and executed arbitrary attacker-supplied JavaScript.
StegoAd is a long-running (2021–2026), financially motivated browser-extension supply-chain campaign that Microsoft's Edge Extensions Security Team disrupted in June 2026 by removing 119 malicious Edge Add-ons and suspending more than 90 associated developer accounts. The extensions impersonated everyday utilities — ad blockers, VPNs, translators, video downloaders, shopping helpers, and color tools — that functioned correctly and accumulated genuine user reviews, allowing them to persist in the Edge Add-ons store for years while quietly amassing an installed base Microsoft caps at up to 2.6 million (explicitly described as a ceiling, not a confirmed-victim count).
The defining tradecraft of the campaign is a four-generation steganographic evolution used to smuggle a JavaScript backdoor past static and dynamic store-review scanning: (1) the earliest variants appended raw JavaScript after the IEND marker of a PNG icon so the image rendered normally everywhere while carrying an invisible payload; (2) as detection improved, the actor shifted to fetching an external PNG from C2 infrastructure with an encoded payload; (3) next, WebP image containers were used with the same append/encode methodology; (4) the actor then moved to WOFF2 web-font files, hiding payload bytes as high-Unicode codepoints in glyph ranges that visually resemble Asian-language text or font metadata; and (5) a March 2026 variant abandoned media steganography for a disguised configuration file (`setting.conf`) containing Base64 payload segments delimited by `/////` sentinels. Across all generations, payload material passes through multiple decode layers — case-swap and digit-swap obfuscation, Base64, XOR, and double-Base64 for exfiltrated data — before execution.
Approximately 66 of the 119 extensions share a common polymorphic delivery framework the actor's own code refers to internally as "orderArray," deployed under 15+ naming variants and composed of an encoded payload object, a seed generator, a regex-based decoder, and a double-Base64 extraction routine. The backdoor delivers roughly 10 distinct payload modules once activated, including credential theft (Google account sign-in interception of both password and second-factor codes, and WordPress administrator login harvesting with pages tagged via SimilarWeb rank data to prioritize high-value targets for double-Base64 exfiltration), bulk session-cookie collection for session hijacking, affiliate-commission hijacking across 20+ Amazon country storefronts plus eBay, AliExpress, Taobao, and JD.com, ad injection/replacement capped at six slots per page across Google AdSense and Amazon ad units, search-result redirection, and a general-purpose remote-code-execution channel that fetches and executes arbitrary JavaScript from C2 within roughly 10 milliseconds of a fingerprint-validated request.
Activation is heavily gated to frustrate analysis and limit mass compromise: extensions enforce a 3–5.5 day post-install dormancy window before any payload logic runs, some variants only activate in roughly 10% of sessions (probabilistic execution gating), and a DevTools-open detection flag (`dipFlgDev`) extends dormancy indefinitely if a user or analyst has developer tools open. C2 servers additionally validate the requesting extension's runtime ID and User-Agent string before serving payload material, returning decoy/benign responses to any probe that fails fingerprint checks.
Command-and-control relies on 10+ domains with automatic failover, fronted and proxied through Cloudflare Workers, with beacon/telemetry hosting abused via GitHub Pages and seven Google Analytics (GA4) tracking IDs used as covert operational dashboards. One credential-exfiltration domain, `mitarchive.info`, was publicly attributed by security firm Koi Security to a Chinese-linked actor it tracks as DarkSpectre, based on Alibaba Cloud-hosted C2 infrastructure, ICP domain registrations tied to Hubei Province, Chinese-language code comments, and fraud schemes targeting Chinese e-commerce platforms (JD.com, Taobao). Koi Security ties the same infrastructure and tradecraft to two earlier extension campaigns, ShadyPanda and GhostPoster (StegoAd reused the extension name "Ads Block Ultimate" from GhostPoster and shares its icon-steganography approach), and a more recent campaign dubbed The Zoom Stealer — together spanning roughly seven years and more than 8.8 million cumulative installs.
The actor also demonstrated active adaptation to platform changes: following Chrome/Edge's Manifest V2-to-V3 migration, which restricted static header-manipulation APIs, the campaign began dynamically fetching `declarativeNetRequest` rules from C2 and reinstalling them every 15 days to preserve header-stripping capability required for its ad-fraud and redirection modules. Attribution signals tying the 119 extensions together despite obfuscation include identical URL path patterns, shared code fingerprints and debug strings, a single shared AdSense publisher ID and matching Google Analytics property IDs, similar developer-account registration metadata, and rapid re-creation of developer accounts following Microsoft suspensions.
Microsoft's response included removing all 119 extensions from the Edge Add-ons store, suspending 90+ developer accounts, shipping new extension-store detection capabilities targeting steganographic payload smuggling, and publishing a full technical report with IOCs and the complete list of affected extension IDs for cross-platform (Chrome, Firefox, Chromium) defenders to check against installed extensions. Microsoft and Koi Security both note the operator remains active.
MITRE ATT&CK techniques used in TL-2026-1221
Command and Control
T1001.002 Steganography; T1008 Fallback Channels; T1071.001 Web Protocols; T1090.002 External Proxy; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1568.002 Domain Generation Algorithms
Collection
T1005 Data from Local System; T1185 Browser Session Hijacking
Defense Evasion
T1027 Obfuscated Files or Information; T1027.003 Steganography; T1027.013 Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1070 Indicator Removal; T1497.001 System Checks
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Credential Access
T1056.003 Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie
Discovery
T1082 System Information Discovery; T1518.001 Security Software Discovery
persistence
Initial Access
T1189 Drive-by Compromise; T1195.002 Compromise Software Supply Chain
Execution
Persistence
Resource Development
T1583.006 Web Services; T1586 Compromise Accounts; T1587.001 Malware
Impact
defense-impairment
Affected products and versions in StegoAd Campaign
- Microsoft — Microsoft Edge Add-ons Store / Extensions
Vulnerable versions: 119 identified extension IDs, Manifest V2 and V3
Fixed in: Extensions removed from store; no version-based fix applies - Google — Google Account sign-in (targeted by credential-theft module)
Vulnerable versions: N/A - targeted via extension content-script interception
Fixed in: N/A - WordPress — WordPress admin login (wp-admin, targeted by credential-theft module)
Vulnerable versions: N/A - targeted via extension content-script interception
Fixed in: N/A
Remediation for StegoAd Campaign
Patches
- No software vulnerability/CVE is involved; remediation is extension removal, not patching
- Update to Edge/Chrome builds with Microsoft's newly deployed extension-store detection capability for steganographic payloads
Immediate actions
- Audit all installed Edge/Chrome/Firefox/Chromium extensions against Microsoft's published StegoAd IOC and extension-ID list
- Remove any extension matching the 119 identified StegoAd extension IDs or the reused name 'Ads Block Ultimate'
- Force logout and rotate credentials (Google account passwords, 2FA/TOTP re-enrollment) for any browser profile that had a flagged extension installed
- Invalidate and rotate session cookies for Google and WordPress admin accounts accessed from affected browsers
- Block C2 domain mitarchive.info and any newly disclosed StegoAd C2 domains at DNS/proxy/firewall layer
- Audit WordPress admin accounts for unauthorized logins or new admin users following suspected exposure
Workarounds
- Restrict extension installation to Microsoft/Google-verified publishers with organizational policy (ExtensionInstallBlocklist/ExtensionInstallAllowlist)
- Disable extension auto-update or gate it through an internal review process for high-privilege categories (ad blockers, VPNs, translators)
Longer-term hardening
- Deploy enterprise browser-extension allowlisting / extension-risk-management tooling instead of relying solely on store vetting
- Monitor outbound traffic for anomalous GitHub Pages beacon requests and Google Analytics (GA4) hits from browser-extension contexts
- Implement steganography-aware static analysis in extension review pipelines (detect trailing data after PNG IEND, anomalous WOFF2 glyph-range entropy, suspicious .conf asset bundling)
- Establish periodic re-review of previously approved extensions, since dormancy windows (3-5.5 days) and low-probability activation (10% of sessions) defeat one-time review
- Track developer-account re-registration patterns to catch rapid recreation after suspension
Weaknesses (CWE) in StegoAd Campaign
Timeline of StegoAd Campaign
- StegoAd threat actor begins operating malicious Edge extension campaign, per Microsoft's assessment of activity dating back to at least 2021.
- Earliest documented technical milestone in Microsoft's timeline: PNG-IEND-marker steganography generation active, marking the start of the formally tracked eight-milestone campaign timeline (March 2024-April 2026).
- Actor evolves steganographic carrier formats from PNG to WebP images and then to WOFF2 font files, hiding payload bytes as high-Unicode glyph-range codepoints resembling Asian-language text, in response to improved detection.
- A new variant abandons media-based steganography, disguising the payload as a 'setting.conf' configuration file containing Base64 segments delimited by '/////' sentinels.
- Following Manifest V2-to-V3 migration constraints on static header manipulation, the actor begins dynamically fetching declarativeNetRequest rules from C2 and reinstalling them every 15 days to preserve ad-fraud header-stripping capability.
- Microsoft publishes a full technical report with code-level evidence, steganographic decode flows, and the complete list of 119 affected extension IDs plus cross-platform (Chrome, Firefox, Chromium) IOCs for defender use.
- Koi Security publishes independent attribution linking the mitarchive.info exfiltration domain and campaign infrastructure to a Chinese-linked actor it tracks as DarkSpectre, also tying the operation to prior ShadyPanda and GhostPoster campaigns and a newer campaign called The Zoom Stealer.
- Microsoft's Edge Extensions Security Team publicly discloses StegoAd, removes all 119 identified malicious extensions from the Edge Add-ons store, and suspends 90+ associated developer accounts.
Sources cited for StegoAd Campaign
- Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
- Inside StegoAd: How We Disrupted a Massive Malicious Extension Campaign
- Microsoft Edge Security Blog - StegoAd Campaign Analysis (technical report)
- StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years
- Microsoft Pulls 119 Malicious Edge Extensions Hiding Malware in Images
- 119 Edge extensions promised useful tools, instead downloaded malware
- Microsoft dismantles StegoAd campaign using malicious Edge extensions
- Microsoft takes down over 100 malicious Edge extensions hiding malware in images and fonts
- StegoAd: Malware Hidden in 119 Microsoft Edge Extensions
- Active Exploitation Alert: Microsoft Edge Hit by StegoAd Malware via 119 Malicious Extensions
Detection coverage for TL-2026-1221
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1221 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.