Close Menu
    What's Hot

    USMNT squad is full of leaders for World Cup knockouts, and not just captain Ream

    Marcotti’s best XI of World Cup group stage: Messi, Mbappé and who else?

    The dollhouse just got an ingenious design update

    Facebook X (Twitter) Instagram
    Trending
    • USMNT squad is full of leaders for World Cup knockouts, and not just captain Ream
    • Marcotti’s best XI of World Cup group stage: Messi, Mbappé and who else?
    • The dollhouse just got an ingenious design update
    • Opinion | Parents Can’t Give Their Kids Everything. Siblings Can Help.
    • Opinion | Fine, Don’t Prosecute the President. But Release Jack Smith’s Report.
    • Israel and Iran Have Divided Democrats and Republicans. Will They Ever Be the Same?
    • With Final Decisions Ahead, the Supreme Court Is Sharply Divided
    • ‘Erased from history’: A century on from Canada’s anti-Greek riots | Protests News
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts

    adminBy adminJune 29, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts

    Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud.

    The company calls it StegoAd, a mash-up of steganography and adware, and ties 119 extensions to a single threat actor it says has been active since at least 2021.

    The extensions were the kind people install without a second thought: ad blockers, VPNs, translators, video downloaders. Each one did its job and earned reviews. The malicious code stayed dormant until the extension cleared a stack of evasion checks, which is how it sat in the store for years.

    Combined, the 119 extensions had an install base of up to 2.6 million users. Microsoft is clear that this is a ceiling, not a victim count.

    Cybersecurity

    A multi-day delay, server-side validation, and a 10% execution gate on some variants meant the payload never fired for many installs. How many people were actually compromised is not known.

    Code hidden in pictures and fonts

    The trick that names the campaign is steganography: tucking executable code inside files that look completely normal. The earliest variants appended JavaScript after the IEND marker of a PNG icon, so the image rendered fine everywhere while carrying a payload that static scanners never flagged.

    As detection caught up, the actor moved to WebP images, then to WOFF2 font files, hiding code in glyph ranges that read as Asian text or font metadata. Microsoft calls steganography at this scale rare in the browser extension ecosystem.

    Some high-impact variants did not even ship the payload locally. They fetched a normal-looking image from a command-and-control server. The extension decoded it through layers of case swaps, digit swaps, Base64, and XOR, then checked it against a signature before running it.

    The C2 server only served the real file to requests that passed a fingerprint and a User-Agent check; anyone probing it directly, researchers included, got an empty decoy response.

    Extensions also watched for open DevTools and extended their dormancy if they spotted an analyst looking.

    Ad fraud on top, credential theft underneath

    The visible damage was ad fraud: injected ads, hijacked affiliate commissions on Amazon, eBay, and AliExpress, and redirected searches, all skimming money while degrading browsing.

    Microsoft’s analysis of retrieved payloads found a lot more underneath. The payloads included a remote code execution backdoor that ran arbitrary JavaScript pushed from the server. They also stole Google credentials and second-factor codes at sign-in, harvested WordPress admin logins, and exfiltrated cookies in bulk for session hijacking.

    Microsoft says seven Google Analytics tracking IDs appear to have served as covert telemetry, giving the operator near real-time dashboards on the campaign through Google’s own infrastructure.

    The plumbing matched the ambition. Microsoft counts more than ten C2 domains with automatic failover. The actor proxied traffic through Cloudflare Workers and abused GitHub Pages to host beacons.

    Cybersecurity

    A polymorphic framework ran across roughly 66 extensions under 15-plus naming variants, and the operation migrated from Manifest V2 to V3 as the actor adapted to platform changes.

    What to do

    Microsoft says it has removed all 119 extensions and suspended the 90-plus developer accounts behind them. The full list of extension IDs is in the company’s technical report.

    Open edge://extensions and compare your installed add-ons against that list. If anything matches, or if Edge removed one automatically, treat the browser as exposed. Change passwords for Google, WordPress, banking, and other sensitive accounts.

    Review recent sign-in activity, and turn on strong two-factor authentication. Hardware security keys hold up against this kind of credential theft in a way that SMS codes do not. Microsoft published indicators of compromise for use across Chrome, Firefox, and other Chromium browsers.

    StegoAd looks less like a new campaign than a new face on a known one. Its credential payload exfiltrates to mitarchive.info, a domain Koi Security ties to DarkSpectre, the Chinese operation it linked in December to the ShadyPanda and GhostPoster extension campaigns.

    The connection goes beyond the domain. StegoAd hides code inside an extension’s own icon, the same method GhostPoster used months earlier. The two even share extension names, such as Ads Block Ultimate.

    Microsoft has not named the actor, but the overlap is clear. The operator is still active, Microsoft says.

    edge extensions fonts hid images Malware Microsoft removes
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleOpinion | The Trump Vibe Shift Was Just a Mirage
    Next Article Ben Godfrey: Rangers sign ex-Everton defender on season-long loan from Atalanta | Football News
    admin
    • Website

    Related Posts

    Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

    June 29, 2026

    White House Releases Images of the Trump ‘Patriot Passport’

    June 27, 2026

    Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

    June 27, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    USMNT squad is full of leaders for World Cup knockouts, and not just captain Ream

    Marcotti’s best XI of World Cup group stage: Messi, Mbappé and who else?

    The dollhouse just got an ingenious design update

    Opinion | Parents Can’t Give Their Kids Everything. Siblings Can Help.

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by