StegoAd is a widespread malware operation that Microsoft has uncovered and taken down , removing 119 malicious extensions from the official Edge Add-ons Store . The operation, active since at least 2021 , hid malware inside legitimate image and font files, infecting up to 2.6 million users on Edge , Chrome , and Firefox . It is one of the most sophisticated browser extension attacks ever recorded.
See also: DRILLAPP Backdoor targets Ukraine with Microsoft Edge debugging

The name StegoAd comes from the combination of the words steganography and adware. The technique of steganography allows the hiding of executable code inside files that look perfectly normal. Early variants of the operation embedded JavaScript after the IEND of a PNG file, allowing the image to appear normal while carrying a payload that static scanning tools did not detect. As detection methods improved, the attacker moved to WebP images and then to WOFF2, hiding code inside symbols that looked like Asian text or font metadata.
StegoAd ’s 119 extensions included popular app categories such as ad blockers , VPNs , translators, and video downloaders . Each extension was functional and had positive reviews, making it suspicious only to expert analysts. The malicious code remained dormant for 3 to 5 days after installation, bypassing initial security checks and user suspicion. Furthermore, some variants were only activated on 10% of installations, making the true number of victims unknown.
How StegoAd worked: Technical details
StegoAd ’s infrastructure was highly sophisticated. The command-and-control (C2) server served the malicious file only to requests that passed fingerprint and User-Agent checks — anyone who tried to access it directly, including researchers, received an empty decoy response. The extensions also monitored whether the browser’s DevTools were open , extending their inactivity if they detected an analyzer. Microsoft identified more than 10 C2 domains with automatic failover , while traffic was routed through Cloudflare Workers and GitHub Pages to host beacons .
A polymorphic framework was running on approximately 66 extensions under more than 15 naming variations. Notably, the company successfully migrated from Manifest V2 to Manifest V3, bypassing new security restrictions that Google to limit the capabilities of extensions. Microsoft also identified 7 Google Analytics tracking IDs that were acting as hidden telemetry, providing the operator with near-real-time campaign data via Google.
See also: New vulnerability in Microsoft Edge allows bypass of security mechanisms

The visible effects of the operation included ad fraud — embedded ads, affiliate commission fraud on platforms like Amazon , eBay , and AliExpress , as well as search redirection. However, analysis of the payloads revealed much more serious activities: remote code execution backdoors , theft of Google credentials and two-factor authentication codes , harvesting WordPress administrator logins , and bulk cookie extraction for session hijacking .
StegoAd: Similar attacks and broader context
The StegoAd operation is not an isolated incident. In May 2026 , Microsoft , together with Europol , ESET , BitSight , Lumen , and other partners, disrupted the infrastructure of Amadey and StealC — two malware families that were linked to more than 140,000 infected computers worldwide in the first two weeks of May alone, taking down more than 200 C2 servers . In parallel, CISA recently added CVE-2026-11645 , a sandbox escape vulnerability in Chrome V8 , to its list of exploitable vulnerabilities , highlighting the ongoing risks to browser rendering engines. The steganography technique used in StegoAd was first identified by Mozilla’s AI red team (0din) , which discovered similar methods of hiding malicious commands in DNS TXT records .
Microsoft removed all 119 extensions and suspended more than 90 developer accounts associated with them. Users are encouraged to compare their installed extensions to the list the company published. If a match is found — or if Edge automatically removed an extension — they should consider their browser compromised. It is recommended to immediately change passwords for Google , WordPress , bank accounts, and other sensitive services, check recent login activity, and enable strong two-factor authentication . Hardware security keys are more effective than SMS codes against this type of credential theft.
See also: Security updates for Microsoft Edge, Teams and Skype due to zero-days

To protect organizations, experts recommend immediately checking all installed extensions in Edge , Chrome , and Firefox , implementing a whitelist of approved extensions, monitoring for delayed activation patterns in browser logs, and updating browsers to address known vulnerabilities. The full list of 119 malicious extensions by StegoAd is available in Microsoft ’s white paper . The operation represents one of the most extensive and sophisticated outbreaks of malicious browser extensions ever uncovered, and highlights the need for stricter controls in official extension stores.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
