Microsoft removes 119 malicious Edge extensions hiding payloads in images
Source headline: Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Intelligence Summary
Microsoft disabled a campaign of malicious Microsoft Edge add-ons found in the Edge Add-ons store. The extensions hid their payloads inside ordinary image and font files. After installation, they reportedly activated later to steal credentials and generate ad fraud. Microsoft attributes the activity to a single threat actor active since at least 2021 and calls the scheme StegoAd. Users should review installed Edge extensions and remove any untrusted or inactive add-ons.
Recommended Action
Inventory where Microsoft Edge runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.