ShellCodeX
Tools • Events • News • Insights
SEO Checker
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Microsoft removes 119 malicious Edge extensions hiding payloads in images

Source headline: Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 month ago

Intelligence Summary

Microsoft disabled a campaign of malicious Microsoft Edge add-ons found in the Edge Add-ons store. The extensions hid their payloads inside ordinary image and font files. After installation, they reportedly activated later to steal credentials and generate ad fraud. Microsoft attributes the activity to a single threat actor active since at least 2021 and calls the scheme StegoAd. Users should review installed Edge extensions and remove any untrusted or inactive add-ons.

Recommended Action

Inventory where Microsoft Edge runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#credential-theft #ad-fraud #microsoft-edge #edge-add-ons #malicious-extensions #steganography
Original reporting The Hacker News Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Open original source