Affected Systems
Microsoft Edge browser users who installed any of 119 malicious extensions from the official Microsoft Edge Add-ons store. Campaign active since at least 2021, affecting unknown number of users globally. Extensions used steganography to hide payloads in images and fonts.
Exploitation Status
Active campaign confirmed. Microsoft has removed all 119 malicious extensions from the Edge Add-ons store. Threat actor (StegoAd campaign) has been operational since at least 2021. Extensions activated malicious behavior days after installation to evade detection.
Business Impact
Users who installed affected extensions face credential theft and potential ad fraud activity. Delayed activation (days post-install) makes detection and incident scoping difficult. Organizations must identify which users installed these extensions and assess credential compromise. No specific extension names or indicators published yet limits immediate hunting capability. Supply chain risk via official store undermines user trust in vetted extension sources.
Urgency
🟠Within 24 hours
Recommended Actions
- Review Microsoft Edge extension inventory across all endpoints using browser management tools or EDR telemetry to identify installations from the past 3+ years
- Force removal of suspicious extensions and reset credentials for users who installed untrusted or recently removed extensions, prioritizing privileged accounts
- Enable Microsoft Edge enterprise policies to restrict extension installations to approved allowlists only
- Monitor for IOCs related to StegoAd campaign including unusual image/font file downloads from extensions and unexpected credential access patterns
- Educate users on extension risks and establish approval workflow for browser extension requests, even from official stores
