StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years

2026-06-29T14:51:45Z2517a4495e8f0cd0f5ced62f9d1129a9cc84104f2d4183d8d41cf108e911af8d
APTCL-STA-1062CVE-2026-43503Cellebrite-abuse','AryStinger','CASTLESTEALER'DirtyCloneEdgeFBIKDDILinux-kernelMicrosoftRussian-espionageSSUSignal-recovery-keysStegoAdTinyRCTTonRATaccount-takeoverad-fraudbrowser-extensionscredential-theftdata-breachhospitality-sectorphishingprivilege-escalationthird-party-vulnerability

What happened

Feed of SecurityAffairs headlines (Jun 26–29, 2026): Microsoft dismantled the “StegoAd” campaign — 119 malicious Edge extensions with ~2.6M installs that stole credentials and ran ad-fraud for ~2 years. Ukraine’s SSU and the FBI exposed a sustained Russian intelligence campaign harvesting messenger accounts (including misuse of Signal recovery keys) to enable account takeover. KDDI disclosed a breach impacting up to 14.2M email accounts after attackers exploited third‑party software. JFrog published a working exploit for DirtyClone (CVE-2026-43503), a Linux kernel privilege-escalation (CVSS ~8

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2517a4495e8f0cd0f5ced62f9d1129a9cc84104f2d4183d8d41cf108e911af8d
Enrichment time
2026-06-29T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · StegoAd: How 119 Fake Browser Extensions Stole Credentials and Ran Ad Fraud for Two Years · Baitaphish