Microsoft has removed 119 malicious Edge browser extensions and suspended over 90 associated developer accounts in a takedown of “StegoAd,” a long-running malware operation active since at least 2021. The extensions — which included ad blockers, VPNs, translators, and video downloaders — used steganography to conceal executable code within image and font files, stealing credentials and conducting ad fraud once activated.
The malicious payload didn’t activate immediately. Instead, extensions provided genuine functionality to build user trust and accumulate positive reviews before triggering their payload days after installation, following a series of evasion checks. The operation also had extensions on Chrome and Firefox, suggesting a broader campaign across browser ecosystems. Up to 2.6 million users may have installed the affected extensions, though the actual number compromised is unclear due to the evasion logic.
Microsoft has published a technical report with a full list of the removed extensions. Users are advised to check their installed extensions against this list and, if exposed, change passwords for sensitive accounts and enable hardware-backed two-factor authentication.
Sources
- The Hacker News — Microsoft Removes 119 Edge Extensions Linked to StegoAd Campaign
- Microsoft Edge — Inside StegoAd: How We Disrupted a Massive Malicious Extension Campaign
- Risky Biz — Microsoft disrupts StegoAd operation
Commentary
StegoAd is a masterclass in patient, evasive malware distribution. The combination of steganography for payload concealment, delayed activation, and legitimate functionality as cover makes these extensions incredibly difficult to detect through standard review processes. The five-year operational lifespan speaks to how well the technique works.
For defenders, this highlights the persistent blind spot of browser extensions — they sit inside the browser’s trust boundary with access to cookies, credentials, and page content. Enterprise security teams should enforce extension allowlisting, monitor for unexpected extension installations, and treat any browser with a suspect extension as potentially compromised. The fact that StegoAd crossed Chrome, Edge, and Firefox means this isn’t a single-vendor problem — it’s a browser ecosystem problem.
