PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
SOCRadar revealed PEEP, a Chromium-based post-exploitation toolkit that disguises itself as a “Smart Bookmarks” extension and uses forged Secure Preferences values to persist in Chrome and Edge. The toolkit steals browser data, hijacks sessions, and uses a native-messaging bridge to execute host-level commands and manage files, with infrastructure tied to 206.237.30[.]232 and xfjcc[.]fun. #PEEP #SmartBookmarks #SOCRadar #RedExt

Keypoints

  • PEEP masquerades as a browser bookmarks extension to blend into Chrome and Edge.
  • It bypasses Web Store checks by tampering with Chromium Secure Preferences and using sideloading methods.
  • The malware exfiltrates browsing history, cookies, active-tab data, and other session details.
  • A native-messaging host lets PEEP run shell commands, manage files, and discover processes and services.
  • The toolkit uses multiple C2 endpoints for registration, heartbeats, updates, task results, and data exfiltration.

Read More: https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html