# StegoAd Campaign: 119 Malicious Edge Extensions Hid Malware in Images, Fonts, and Config Files, Up to 2.6M Installs

> Microsoft's Edge Security Team disrupted StegoAd, a threat actor operating since at least 2021 across 90+ developer accounts and 119 Microsoft Edge extensions (ad blockers, VPNs, translators, video downloaders, shopping helpers) with a combined install base of up to 2.6 million. The extensions used a four-generation steganography evolution — JavaScript appended after PNG IEND markers, external PNG payloads, WebP containers, WOFF2 font glyph ranges, and finally Base64 'setting.conf' files — to smuggle a polymorphic backdoor ("orderArray" framework) that stole Google/WordPress credentials and session cookies, hijacked affiliate links, injected ads, and executed arbitrary attacker-supplied JavaScript.

- **Published:** 2026-07-11T00:00:00Z
- **Last reviewed:** 2026-07-11T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1221
- **ID:** TL-2026-1221
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** DarkSpectre (China)
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

StegoAd is a long-running (2021–2026), financially motivated browser-extension supply-chain campaign that Microsoft's Edge Extensions Security Team disrupted in June 2026 by removing 119 malicious Edge Add-ons and suspending more than 90 associated developer accounts. The extensions impersonated everyday utilities — ad blockers, VPNs, translators, video downloaders, shopping helpers, and color tools — that functioned correctly and accumulated genuine user reviews, allowing them to persist in the Edge Add-ons store for years while quietly amassing an installed base Microsoft caps at up to 2.6 million (explicitly described as a ceiling, not a confirmed-victim count).

The defining tradecraft of the campaign is a four-generation steganographic evolution used to smuggle a JavaScript backdoor past static and dynamic store-review scanning: (1) the earliest variants appended raw JavaScript after the IEND marker of a PNG icon so the image rendered normally everywhere while carrying an invisible payload; (2) as detection improved, the actor shifted to fetching an external PNG from C2 infrastructure with an encoded payload; (3) next, WebP image containers were used with the same append/encode methodology; (4) the actor then moved to WOFF2 web-font files, hiding payload bytes as high-Unicode codepoints in glyph ranges that visually resemble Asian-language text or font metadata; and (5) a March 2026 variant abandoned media steganography for a disguised configuration file (`setting.conf`) containing Base64 payload segments delimited by `/////` sentinels. Across all generations, payload material passes through multiple decode layers — case-swap and digit-swap obfuscation, Base64, XOR, and double-Base64 for exfiltrated data — before execution.

Approximately 66 of the 119 extensions share a common polymorphic delivery framework the actor's own code refers to internally as "orderArray," deployed under 15+ naming variants and composed of an encoded payload object, a seed generator, a regex-based decoder, and a double-Base64 extraction routine. The backdoor delivers roughly 10 distinct payload modules once activated, including credential theft (Google account sign-in interception of both password and second-factor codes, and WordPress administrator login harvesting with pages tagged via SimilarWeb rank data to prioritize high-value targets for double-Base64 exfiltration), bulk session-cookie collection for session hijacking, affiliate-commission hijacking across 20+ Amazon country storefronts plus eBay, AliExpress, Taobao, and JD.com, ad injection/replacement capped at six slots per page across Google AdSense and Amazon ad units, search-result redirection, and a general-purpose remote-code-execution channel that fetches and executes arbitrary JavaScript from C2 within roughly 10 milliseconds of a fingerprint-validated request.

Activation is heavily gated to frustrate analysis and limit mass compromise: extensions enforce a 3–5.5 day post-install dormancy window before any payload logic runs, some variants only activate in roughly 10% of sessions (probabilistic execution gating), and a DevTools-open detection flag (`dipFlgDev`) extends dormancy indefinitely if a user or analyst has developer tools open. C2 servers additionally validate the requesting extension's runtime ID and User-Agent string before serving payload material, returning decoy/benign responses to any probe that fails fingerprint checks.

Command-and-control relies on 10+ domains with automatic failover, fronted and proxied through Cloudflare Workers, with beacon/telemetry hosting abused via GitHub Pages and seven Google Analytics (GA4) tracking IDs used as covert operational dashboards. One credential-exfiltration domain, `mitarchive.info`, was publicly attributed by security firm Koi Security to a Chinese-linked actor it tracks as DarkSpectre, based on Alibaba Cloud-hosted C2 infrastructure, ICP domain registrations tied to Hubei Province, Chinese-language code comments, and fraud schemes targeting Chinese e-commerce platforms (JD.com, Taobao). Koi Security ties the same infrastructure and tradecraft to two earlier extension campaigns, ShadyPanda and GhostPoster (StegoAd reused the extension name "Ads Block Ultimate" from GhostPoster and shares its icon-steganography approach), and a more recent campaign dubbed The Zoom Stealer — together spanning roughly seven years and more than 8.8 million cumulative installs.

The actor also demonstrated active adaptation to platform changes: following Chrome/Edge's Manifest V2-to-V3 migration, which restricted static header-manipulation APIs, the campaign began dynamically fetching `declarativeNetRequest` rules from C2 and reinstalling them every 15 days to preserve header-stripping capability required for its ad-fraud and redirection modules. Attribution signals tying the 119 extensions together despite obfuscation include identical URL path patterns, shared code fingerprints and debug strings, a single shared AdSense publisher ID and matching Google Analytics property IDs, similar developer-account registration metadata, and rapid re-creation of developer accounts following Microsoft suspensions.

Microsoft's response included removing all 119 extensions from the Edge Add-ons store, suspending 90+ developer accounts, shipping new extension-store detection capabilities targeting steganographic payload smuggling, and publishing a full technical report with IOCs and the complete list of affected extension IDs for cross-platform (Chrome, Firefox, Chromium) defenders to check against installed extensions. Microsoft and Koi Security both note the operator remains active.

## MITRE ATT&CK

- T1195.002 Compromise Software Supply Chain
- T1189 Drive-by Compromise
- T1176 Software Extensions
- T1204.002 Malicious File
- T1505.003 Web Shell
- T1027 Obfuscated Files or Information
- T1027.003 Steganography
- T1027.013 Encrypted/Encoded File
- T1497.001 System Checks
- T1685 Disable or Modify Tools
- T1036.005 Match Legitimate Resource Name or Location
- T1070 Indicator Removal
- T1056.003 Web Portal Capture
- T1539 Steal Web Session Cookie
- T1111 Multi-Factor Authentication Interception
- T1528 Steal Application Access Token
- T1518.001 Security Software Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1185 Browser Session Hijacking
- T1071.001 Web Protocols
- T1001.002 Steganography
- T1090.002 External Proxy
- T1102.002 Bidirectional Communication
- T1568.002 Domain Generation Algorithms
- T1008 Fallback Channels
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft
- T1586 Compromise Accounts
- T1583.006 Web Services
- T1587.001 Malware

## Sources

- [Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts](https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html)
- [Inside StegoAd: How We Disrupted a Massive Malicious Extension Campaign](https://microsoftedge.github.io/edgevr/posts/Inside-StegoAd-How-We-Disrupted-a-Massive-Malicious-Extension-Campaign/)
- [Microsoft Edge Security Blog - StegoAd Campaign Analysis (technical report)](https://microsoftedge.github.io/edgevr/assets/files/stego_ad/Microsoft_Edge_Security_StegoAd.pdf)
- [StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years](https://securityaffairs.com/194409/malware/stegoad-how-119-fake-browser-extensions-stole-credentials-and-ran-ad-fraud-for-two-years.html)
- [Microsoft Pulls 119 Malicious Edge Extensions Hiding Malware in Images](https://www.techtimes.com/articles/319365/20260630/microsoft-pulls-119-malicious-edge-extensions-hiding-malware-images.htm)
- [119 Edge extensions promised useful tools, instead downloaded malware](https://www.malwarebytes.com/blog/news/2026/06/119-edge-extensions-promised-useful-tools-instead-downloaded-malware)
- [Microsoft dismantles StegoAd campaign using malicious Edge extensions](https://www.scworld.com/brief/microsoft-dismantles-stegoad-campaign-using-malicious-edge-extensions)
- [Microsoft takes down over 100 malicious Edge extensions hiding malware in images and fonts](https://www.techradar.com/pro/security/microsoft-takes-down-over-100-malicious-edge-extensions-hiding-malware-in-images-and-fonts)
- [StegoAd: Malware Hidden in 119 Microsoft Edge Extensions](https://www.it-connect.tech/stegoad-malware-hidden-in-119-microsoft-edge-extensions/)
- [Active Exploitation Alert: Microsoft Edge Hit by StegoAd Malware via 119 Malicious Extensions](https://www.rescana.com/post/active-exploitation-alert-microsoft-edge-hit-by-stegoad-malware-via-119-malicious-extensions-affecting-over-2-6-million)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1221
