SOCRadar revealed PEEP, a Chromium-based post-exploitation toolkit that disguises itself as a “Smart Bookmarks” extension and uses forged Secure Preferences values to persist in Chrome and Edge. The toolkit steals browser data, hijacks sessions, and uses a native-messaging bridge to execute host-level commands and manage files, with infrastructure tied to 206.237.30[.]232 and xfjcc[.]fun. #PEEP #SmartBookmarks #SOCRadar #RedExt
Keypoints
- PEEP masquerades as a browser bookmarks extension to blend into Chrome and Edge.
- It bypasses Web Store checks by tampering with Chromium Secure Preferences and using sideloading methods.
- The malware exfiltrates browsing history, cookies, active-tab data, and other session details.
- A native-messaging host lets PEEP run shell commands, manage files, and discover processes and services.
- The toolkit uses multiple C2 endpoints for registration, heartbeats, updates, task results, and data exfiltration.
Read More: https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html