Signal

Microsoft removes 119 malicious Edge extensions involved in credential theft and ad fraud

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-29 08:32 UTCUpdated 2026-06-29 14:41 UTC
rss
malwarebrowser_extensionscredential_theftad_fraudincident_response
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Malwarebytes Threat Analysis
malwarebytes.com · malwarebytes.com · 2026-06-29 14:41 UTC
The Hacker News
thehackernews.com · thehackernews.com · 2026-06-29 08:32 UTC
limited source diversity in top sources
Overview

Microsoft has taken down 119 malicious extensions from the Edge Add-ons store linked to a single threat actor active since at least 2021.

Entities
MicrosoftStegoAd
Score total
1.03
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • Microsoft’s recent takedown disrupts a long-running malicious campaign active since 2021.
  • The large number of affected users highlights ongoing risks in browser extension ecosystems.
  • Revealing sophisticated malware techniques informs defenders and users about emerging threats.
Why it matters
  • Browser extensions can be abused to deliver malware at scale, impacting millions of users.
  • Steganography techniques enable malware to evade traditional detection methods.
  • Credential theft and ad fraud campaigns pose significant risks to user security and privacy.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • 119 Edge extensions downloaded by 2.6 million users secretly delivered malware after initial installation
  • Malware used steganography to hide payloads inside images and fonts to evade detection
  • Malicious extensions stole Google credentials, two-factor codes, WordPress admin logins, and session cookies
How sources frame it
  • Microsoft Researchers: neutral
  • The Hacker News: neutral
This incident underscores the evolving threat landscape in browser extensions, highlighting the need for vigilant vetting and monitoring of add-ons.
All evidence
All evidence
Malwarebytes Threat Analysis
malwarebytes.com · malwarebytes.com · 2026-06-29 14:41 UTC
The Hacker News
thehackernews.com · thehackernews.com · 2026-06-29 08:32 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • malwarebytes.com (1)
  • thehackernews.com (1)
Top origin domains (this list)
  • malwarebytes.com (1)
  • thehackernews.com (1)