Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Is A Free VPN Worth Using? Here’s Why It Could Be Risky

    September 12, 2026

    Researchers link another hacking campaign to OpenAI agents

    September 12, 2026

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
    Cybersecurity

    PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

    InfoForTechBy InfoForTechSeptember 8, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.

    “Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences integrity values,” SOCRadar said. “A native-messaging tool then extends it beyond browser telemetry to host-level command execution and file management.”

    Once installed, the PEEP “extension” agent polls its command-and-control (C2) server (“206.237.30[.]232” or “xfjcc[.]fun“) every 30 seconds over plaintext HTTP for new commands, while exfiltrating browsing history, active-tab metadata, and session cookies. It also functions as a remote access and browser monitoring toolkit that runs host commands, steals credentials, hijacks sessions, and alters web pages.

    PEEP is built on the foundations of RedExt, an open-source, browser data analysis and red teaming framework that has also been put to use in prior GlassWorm attacks. However, it expands on the toolkit with dedicated installation routines, a native host bridge, heartbeat telemetry, an update channel, and a broader command set. This, in turn, makes PEEP a derivative of RedExt.

    PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the operator to breach a machine through some other means and deploy the malware. The activity remains unattributed, although the presence of Chinese-language artifacts in the source code points to a Chinese-speaking threat actor.

    The extension masquerades as “Smart Bookmarks” (ID: ejkndncpkdcjcikfhiamcdehdoegilbj). It’s the main agent responsible for executing the beacon loop by polling “/api/commands,” harvesting browser data, receiving additional tasking, and sending the results back.

    The browser add-on also invokes an auxiliary executable (“nm_host.exe”) when said task requires operating system access, while browser-based commands (e.g., screenshots, clipboard, or JavaScript injection) are run locally. The use of the Native Messaging Host binary transforms the malware from a basic credential stealer to a remote-access tool.

    “Operating in the user context, the extension extracts browser artifacts and uses com.peep.lab/nm_host.exe to run shell commands, manage files, and discover processes and services,” SOCRadar said. “Bypassing Web Store checks, PEEP maintains persistence via sideloading, enterprise force-install policies, preference-integrity manipulation, and a ScriptCache fallback.”

    Also used by the extension are several other endpoints –

    • “/api/register” to register the infection
    • “/api/agents//heartbeat” to send details about the browser’s User-Agent string, operating system, and time zone
    • “/api/extension_update/” and “/api/extension_crx/” to update the extension itself
    • “/api/agents//task_result” to post the results of the command execution
    • “/api/exfil” to post auto-collected data, such as cookies, recent history, open tabs, active URL, public IP address, locale, and time zone
    • “/health” to serve internal system status without requiring login credentials
    • “/login” to serve a login interface for the C2 panel at port 5001

    Another defining aspect of PEEP is its ability to modify the Secure Preferences file to ensure that the extension is auto-enabled upon launching the browser. Given that the extension is not available on the Chrome Web Store and other official extension marketplaces, it also leverages the ExtensionInstallForcelist or ExtensionSettings policies and sideloading tricks for delivery.

    the malware makes use of two PowerShell scripts, while a third one acts as a re-registration helper for the extension without touching Secure Preferences –

    • install_silent.ps1, which enables Developer Mode to sideload arbitrary extensions
    • patch_secure_prefs.ps1, which patches the Secure Preferences file
    • force_enable.ps1, which removes the extension from Preferences’s external_uninstalls, places the CRX at %LOCALAPPDATA%PEEPcrx, re-registers via the HKCU Extensions key and an External Extensions JSON manifest, and restarts the browser

    There also exists a Python script named “patch_secure_prefs_linux.py” with the same function as its PowerShell counterpart, indicating that the threat actor behind the operation is replicating the behavior to also target Linux environments.

    Once initialized, the extension parses a configuration file to extract C2 information and activate automated data harvesting, while a companion content script (“content.js”) is embedded across all active web pages.

    SOCRadar said it identified a number of references to “Authorized CTF” use, raising the possibility that the threat actor may have used the framing to lower the safety guardrails of AI tools and assist in malware development. There are currently no signs as to who is being targeted, but the “/health” endpoint shows 34 agent entries, 10 active sessions, and 507 data records. That said, there is no way to differentiate actual infected hosts from test entries or verified deployments.

    “PEEP builds on existing host compromises, using a native-messaging bridge to convert Chrome/Edge into a persistent backdoor that crosses the browser sandbox to reach the OS,” SOCRadar said. “Because its logic runs inside the signed browser process, it slips past detection of keys on new or unsigned binaries. Consequently, the browser acts as an endpoint pivot for credential theft, session abuse, and command execution.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026

    Best Practices for Deception Technology Implementation

    September 12, 2026

    Weekly Update 521: Breach Perception v. Reality

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026

    JADEPUFFER’s Second Wave Multi-Agent Attacks

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.