Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
A long-running malicious extension operation on the Edge Add-ons store that concealed its payloads inside regular image and font files before waking up days after installation to steal passwords and do ad fraud has been shut down by Microsoft.
The business refers to it as StegoAd, a combination of adware and steganography, and links 119 extensions to a single threat actor that it claims has been operating since at least 2021.
Ad blockers, VPNs, movie downloaders, and translators were among the extensions that consumers installed mindlessly. They all performed well and received praise. The harmful code remained dormant for years in the store until the extension passed a series of evasion checks.
Up to 2.6 million people had installed all 119 extensions combined. Microsoft is adama...

