As cited
Copy frozen at (site build).
threat intel
Risky Bulletin: Microsoft disrupts StegoAd operation
Microsoft removed 119 malicious extensions from the Edge Add-ons store that were part of a coordinated StegoAd operation designed to steal credentials, inject backdoors, and conduct affiliate fraud. The extensions used steganography to conceal malicious commands and operated across multiple developer accounts while sharing infrastructure and code. The same threat actors deployed similar extensions on Chrome and Firefox.
Why it matters: Browser extension users on Edge, Chrome, and Firefox face credential theft and browser hijacking risks; practitioners should audit their organizations' extension policies and recommend users review installed extensions for suspicious behavior.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Risky Bulletin: Microsoft disrupts StegoAd operation
Microsoft removed 119 malicious extensions from the Edge Add-ons store that were part of a coordinated StegoAd operation designed to steal credentials, inject backdoors, and conduct affiliate fraud. The extensions used steganography to conceal malicious commands and operated across multiple developer accounts while sharing infrastructure and code. The same threat actors deployed similar extensions on Chrome and Firefox.
Why it matters: Browser extension users on Edge, Chrome, and Firefox face credential theft and browser hijacking risks; practitioners should audit their organizations' extension policies and recommend users review installed extensions for suspicious behavior.
- Source published
- First seen by Cybersecurity Tracker