# Microsoft Purges 119 Malicious Edge Extensions in Stealthy 5-Year Ad-Fraud and Credential-Theft Campaign


Microsoft has dismantled a sophisticated malware operation targeting Edge browser users that hid executable code inside innocent-looking images and fonts, remaining dormant for days after installation to evade detection. The campaign, which Microsoft calls StegoAd, compromised up to 2.6 million users across 119 extensions operating under a single threat actor since at least 2021.


The extensions appeared legitimate—ad blockers, VPN tools, translators, and video downloaders with genuine user reviews. The malicious payload never fired for many installations due to multi-layered evasion checks, but enough executions succeeded to conduct widespread ad fraud, credential theft, and establish remote access backdoors on compromised systems.


## The Threat


The StegoAd campaign represents a rare combination of scale, sophistication, and persistence in the browser extension ecosystem. The 119 extensions, which collectively earned positive user ratings and operated openly in Microsoft's official store, carried layered payloads designed to:


  • Inject fraudulent advertisements into web pages and hijack affiliate commissions on major marketplaces (Amazon, eBay, AliExpress)
  • Steal credentials for Google accounts, WordPress admin panels, and banking services
  • Harvest cookies for session hijacking and account takeover
  • Establish remote code execution backdoors capable of running arbitrary JavaScript from attacker-controlled servers
  • Exfiltrate second-factor authentication codes during sign-in events

  • Microsoft's analysis reveals the operation used seven Google Analytics tracking IDs as covert telemetry channels, giving the attacker near real-time visibility into campaign performance and victim behavior through Google's own infrastructure—a particularly bold misdirection.


    The malware persisted in the official Edge Add-ons store for years, undetected by both Microsoft's vetting and automated scanners.


    ## Technical Architecture: Steganography at Scale


    The campaign's defining technique is steganography—embedding executable code inside files that appear completely normal. This approach bypassed traditional file-based detection systems that examine code directly.


    ### Evolution of Encoding Methods


    | Generation | Technique | Detection Status |

    |-----------|-----------|------------------|

    | Early variants | JavaScript appended after PNG IEND marker | Detected; scanner bypassed |

    | Mid-evolution | WebP image container abuse | Detected; migrated |

    | Latest stage | WOFF2 font file glyph ranges | Rare detection |


    The attacker appended JavaScript after the IEND marker of PNG files, allowing the image to render normally across all browsers while carrying a payload that static analysis tools never flagged. As detection improved, the actor migrated to WebP containers, then to WOFF2 font files, embedding code in glyph ranges that read as Asian text or font metadata—a technique Microsoft describes as exceptionally rare in the extension ecosystem.


    Some high-impact variants employed an even more sophisticated approach: the extension fetched what appeared to be a normal image from a command-and-control server. The malware then decoded it through multiple obfuscation layers (case swaps, digit swaps, Base64, and XOR encoding) before validating the signature and executing the payload. The C2 server only served the actual malicious file to requests that passed both fingerprint and User-Agent validation; anyone probing it directly received an empty decoy response.


    ### Evasion and Persistence


    The extensions actively monitored for analyst activity—specifically the presence of open DevTools—and extended their dormancy period if they detected a security researcher examining the code. This multi-day delay, combined with server-side validation gates and a 10% execution threshold on some variants, meant the payload never fired for many installations despite their presence in the store.


    The infrastructure supporting the campaign was equally resilient:

  • 10+ C2 domains with automatic failover
  • Traffic proxying through Cloudflare Workers to obscure attacker infrastructure
  • Beacon hosting on GitHub Pages
  • Polymorphic framework deployed across 66+ extensions under 15 naming variants
  • Manifest V3 migration, showing the actor actively adapted to platform deprecation of V2

  • ## Background and Context


    The StegoAd campaign emerged in a period when browser extension security received limited scrutiny from major vendors. Extensions requested broad permissions—access to all sites, cookie modification, network traffic inspection—that are standard for legitimate tools but catastrophic in malicious hands.


    Microsoft's security team identified the earliest variants dating to 2021, meaning the operation remained undetected for approximately five years. The extensions populated the official store with convincing user reviews, install counts, and functionality that matched their descriptions. A translator extension translated; an ad blocker blocked ads. The Trojan work happened in the background, after approval gates had cleared.


    The 2.6 million install figure, Microsoft cautions, represents the upper ceiling. Not all installs executed the payload due to the deliberate dormancy period, validation gates, and execution thresholds built into the framework. The actual number of compromised users is lower—but remains unknown.


    ## Implications for Organizations and Users


    This campaign reveals critical gaps in browser extension security:


    For enterprises: Browser extensions operate with minimal oversight compared to installed software. An extension flagged during organizational rollout may have already compromised credentials and established persistence before IT teams notice unusual network traffic.


    For individuals: Installing an extension grants it permissions equivalent to admin access for that browser. Malicious code hidden in steganographic payloads can remain undetected indefinitely if the infrastructure supporting execution is sophisticated enough.


    For platforms: Microsoft's store hosted these extensions for years despite their presence. The steganography technique and multi-layered evasion meant traditional malware scanning failed—a problem likely affecting other extension marketplaces that use similar detection methods.


    ## Recommendations


    ### Immediate Actions for Users


  • Check your extensions now: Open edge://extensions and compare your installed add-ons against the [complete list of 119 extension IDs](https://www.microsoft.com/en-us/security/blog/) in Microsoft's technical report.
  • Assume breach if any extension matched: Treat your browser as exposed.
  • Change passwords immediately for Google, WordPress, banking, and any other sensitive service. Prioritize accounts that leverage the affected browser.
  • Review recent sign-in activity in your Google account's [Security Checkup](https://myaccount.google.com/security-checkup).
  • Enable hardware security keys where available (Gmail, GitHub, Microsoft accounts support these). Hardware keys are immune to credential theft via malware—they cannot be phished or stolen by code running on the victim's machine.

  • ### For Organizations


  • Audit extension deployment policies: If your organization permits user-installed extensions, establish an allowlist rather than a blocklist. Require IT approval before installation.
  • Monitor for indicators of compromise: Recent creation of new browser profiles, unusual outbound connections to ad networks, spike in affiliate redirect clicks from internal traffic, and new cloud service sign-ins from unexpected locations.
  • Reset credentials for administrators: WordPress admins, cloud service accounts, and email are high-value targets.

  • ### For Extension Developers


  • Use code signing: Microsoft and other platforms should require signed code that cannot be embedded steganographically.
  • Prohibit remote code execution: Restrict extensions' ability to fetch and execute code from external servers.
  • Limit network capabilities: Extensions should declare the specific domains they communicate with; catch-all permissions should trigger deeper review.

  • ## HackWire Analysis


    The StegoAd campaign exposes a fundamental architectural flaw in browser extension security: we've optimized extensions for user convenience and developer freedom while treating detection as an afterthought. Microsoft's vetting process flagged none of these 119 extensions despite a five-year presence because steganography—embedding code in images and fonts—flies below the radar of automated scanners designed to detect malicious JavaScript.


    This isn't a failure unique to Microsoft. The pattern appears across extension ecosystems: vendors prioritize user experience and rapid third-party development over restrictive permission models. Every major browser extension platform has versions of this same vulnerability—a wide attack surface with limited visibility into what code actually executes at runtime.


    What's particularly notable is the campaign's sophistication relative to its prevalence. The attacker used Google Analytics as a telemetry channel, Cloudflare Workers for traffic proxying, GitHub Pages for beacon hosting, and polymorphic code that adapted to Manifest V3. This isn't script-kiddie malware; it's a well-resourced operation with infrastructure discipline and long-term staying power. The use of steganography specifically—a technique rarely seen at this scale in extensions—suggests the operator studied detection mechanisms in detail and engineered around them.


    The real risk isn't the ad fraud, though that's lucrative. It's the credential theft and session hijacking infrastructure beneath it. An attacker with access to Google credentials, WordPress admin accounts, and bulk cookies can establish persistent footholds in web properties, email, and content management systems. Hardware security keys stop this attack cold—a concrete countermeasure that's finally becoming mainstream.


    The broader pattern: vendors detect large-scale threats after victim count reaches the millions, not before. Until extension markets enforce code signing, restrict remote execution, and audit permissions ruthlessly, expect this cycle to repeat. — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)