Risky Bulletin Newsletter
June 29, 2026
Risky Bulletin: Microsoft disrupts StegoAd operation
Presented by
News Editor
Microsoft's security team has removed 119 malicious Edge extensions from the official Microsoft Edge Add-ons store that were part of a coordinated operation that sought to steal user credentials, backdoor browsers, and engage in advertising and search affiliate fraud.
The extensions were published through 90+ different developer accounts but shared infrastructure, parts of their codebase, and heavily relied on steganography to hide malicious commands and code.
The StegoAd operation, as Microsoft called it, also had Chrome and Firefox extensions under its umbrella.