← All stories
● Covered by 1 source · 1 reportHigh impact

Microsoft Removes 119 Malicious Edge Extensions Involved in Malware Operation

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 119 malicious Edge extensions removed by Microsoft.
  • Extensions hid malware in images and fonts using steganography.
  • Affected up to 2.6 million users with ad fraud and credential theft.

Malicious Extension Operation Uncovered

Microsoft has terminated a campaign involving 119 malicious extensions in its Edge Add-ons store. These extensions masqueraded as benign tools—such as ad blockers and video downloaders—but contained hidden payloads that were activated post-installation. The campaign, dubbed StegoAd, has been linked to a single threat actor active since at least 2021.

Steganography Techniques Employed

The malicious code was cleverly concealed using steganography, embedding executable scripts within standard image and font files. Initially, these scripts were placed after the IEND marker of PNG files, allowing them to appear harmless to security scanners. As detection methods improved, the actor adapted by using more sophisticated file types like WebP images and WOFF2 font files.

Impact on Users and Browsing Security

The extensions potentially impacted an extensive user base, with Microsoft estimating that up to 2.6 million installations occurred. The exact number of compromised users is unclear, as many installations did not execute the malicious payload due to various checks put in place by the attackers. However, the visible effects included ad fraud, hijacking affiliate commissions on platforms such as Amazon and eBay, and redirecting search queries.

Comprehensive Threat Analysis

In addition to ad fraud, the payloads retrieved by Microsoft encompassed capabilities for remote code execution, indicating the extensive threat posed by these extensions. The operational sophistication included mechanisms to evade detection by monitoring for security tools and analysts, allowing the malicious activities to remain under the radar for an extended period.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Microsoft has removed 119 Edge extensions from its Add-ons store that concealed malware within images and fonts, compromising user credentials and facilitating ad fraud. The extensions, installed by up to 2.6 million users, utilized steganography to hide malicious code, operating undetected for years.