Overview
- Microsoft disclosed Monday that it removed 119 malicious Edge extensions, suspended more than 90 developer accounts, and published a technical report plus indicators of compromise for Chromium browsers.
- The campaign, tracked back to at least 2021, used steganography to hide executable JavaScript inside PNG, WebP and WOFF2 files and later in disguised config files so static scanners saw only normal images or fonts.
- Payloads delivered ad fraud such as injected ads and affiliate hijacks while also carrying a remote code execution backdoor that stole Google credentials, intercepted 2FA codes, harvested WordPress admin logins, and exfiltrated cookies.
- Operators used delayed activation, session gating, DevTools detection, runtime fingerprinting and failover C2 domains plus legitimate services like Google Analytics, GitHub Pages and Cloudflare to hide telemetry and survive removals.
- Users should check edge://extensions against Microsoft’s published extension IDs, remove any matches, rotate passwords for sensitive accounts, and use hardware security keys where possible to block intercepted 2FA codes.