BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

PEEP malware: Chrome extension hijacks browsers, steals data

PEEP post-exploit browser toolkit fakes bookmarks extension, bypasses Chrome checks, steals credentials and hijacks sessions

  • Researchers at SOCRadar uncovered a Chrome/Edge post-exploitation toolkit called PEEP that masquerades as a “Smart Bookmarks” extension.
  • The malware bypasses Web Store checks by forging Chromium’s Secure Preferences, deploying via sideloading and enterprise policies.
  • PEEP uses a native-messaging host to cross the browser sandbox, enabling remote command execution, credential theft, and session hijacking.
  • The toolkit, derived from open-source RedExt framework, appears linked to a Chinese-speaking threat actor based on code artifacts.

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. The malware requires prior administrative or code execution access, and its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks by forging Chromium’s own Secure Preferences integrity values.

- Advertisement -

Once installed, the “extension” agent polls its command-and-control server (“206.237.30[.]232” or “xfjcc[.]fun“) every 30 seconds over plaintext HTTP for new commands. It exfiltrates browsing history, active-tab metadata, and session cookies while also functioning as a remote access toolkit that runs host commands and steals credentials.

PEEP builds on the open-source RedExt framework, previously used in GlassWorm attacks, but expands with dedicated installation routines, a native host bridge, heartbeat telemetry, and a broader command set. The activity remains unattributed, though Chinese-language artifacts in source code point to a Chinese-speaking threat actor.

The extension uses a native-messaging binary (“nm_host.exe”) to transform from a credential stealer into a remote-access tool. It invokes this binary when tasks require operating system access, while browser-based commands like screenshots or JavaScript injection run locally. SOCRadar noted: “Operating in the user context, the extension extracts browser artifacts and uses com.peep.lab/nm_host.exe to run shell commands, manage files, and discover processes and services.”

To ensure persistence, PEEP modifies the Secure Preferences file to auto-enable the extension on browser launch. It uses PowerShell scripts to enable Developer Mode, patch Secure Preferences, and force installation via registry keys and external extension manifests. A Python script “patch_secure_prefs_linux.py” suggests the threat actor is also targeting Linux environments.

- Advertisement -

The extension parses a configuration file to extract C2 information and activate automated data harvesting, while a companion content script is embedded across all active web pages. SOCRadar identified references to “Authorized CTF” use, possibly to lower AI tool safety guardrails for malware development. The “/health” endpoint shows 34 agent entries, 10 active sessions, and 507 data records, though test entries cannot be distinguished from actual infections.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BitMine nears 5% of Ether supply, could hit target by November

BitMine Immersion Technologies currently holds 6,001,302 ETH, representing 4.9% of total supply, and needs...

MCP Python SDK OAuth flaw lets attackers steal credentials

High-severity OAuth credential theft flaw found in MCP Python SDK versions 1.9.1–1.29.1 and 2.0.0–2.1.1.Attacker-controlled...

Can BNB Coin Reclaim $1000 After 45% Slump?

BNB hit an all-time high of $1,369.99 in October 2025 but has since declined...

BTIG Boosts Robinhood Target to $135 on Solid Q3 Metrics

BTIG raised Robinhood's price target to $135 from $125, maintaining a Buy rating with...

Blockchain.com eyes $500M IPO as crypto capital markets thaw

Blockchain.com is reportedly targeting a $500 million initial public offering in 2026, seeking a...

Must Read

6 Best VPN Providers That Accept Monero

Privacy and anonymity are probably the most important things that we should all consider in today's internet era. Although there are a lot of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading