MEDIUMMalware
Global

Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts

·Source: The Hacker News

Updated:

Executive Summary

Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud. The company calls it StegoAd, a mash-up of steganography and adware, and ties 119 extensions to a single threat actor it says has been active since at least 2021.

Analysis

Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud. The company calls it StegoAd, a mash-up of steganography and adware, and ties 119 extensions to a single threat actor it says has been active since at least 2021.
Source Attribution

Originally published by The Hacker News on Jun 29, 2026.

Related Threats