BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

PEEP malware: Chrome extension hijacks browsers, steals data

PEEP post-exploit browser toolkit fakes bookmarks extension, bypasses Chrome checks, steals credentials and hijacks sessions

  • Researchers at SOCRadar uncovered a Chrome/Edge post-exploitation toolkit called PEEP that masquerades as a “Smart Bookmarks” extension.
  • The malware bypasses Web Store checks by forging Chromium’s Secure Preferences, deploying via sideloading and enterprise policies.
  • PEEP uses a native-messaging host to cross the browser sandbox, enabling remote command execution, credential theft, and session hijacking.
  • The toolkit, derived from open-source RedExt framework, appears linked to a Chinese-speaking threat actor based on code artifacts.

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. The malware requires prior administrative or code execution access, and its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks by forging Chromium’s own Secure Preferences integrity values.

- Advertisement -

Once installed, the “extension” agent polls its command-and-control server (“206.237.30[.]232” or “xfjcc[.]fun“) every 30 seconds over plaintext HTTP for new commands. It exfiltrates browsing history, active-tab metadata, and session cookies while also functioning as a remote access toolkit that runs host commands and steals credentials.

PEEP builds on the open-source RedExt framework, previously used in GlassWorm attacks, but expands with dedicated installation routines, a native host bridge, heartbeat telemetry, and a broader command set. The activity remains unattributed, though Chinese-language artifacts in source code point to a Chinese-speaking threat actor.

The extension uses a native-messaging binary (“nm_host.exe”) to transform from a credential stealer into a remote-access tool. It invokes this binary when tasks require operating system access, while browser-based commands like screenshots or JavaScript injection run locally. SOCRadar noted: “Operating in the user context, the extension extracts browser artifacts and uses com.peep.lab/nm_host.exe to run shell commands, manage files, and discover processes and services.”

To ensure persistence, PEEP modifies the Secure Preferences file to auto-enable the extension on browser launch. It uses PowerShell scripts to enable Developer Mode, patch Secure Preferences, and force installation via registry keys and external extension manifests. A Python script “patch_secure_prefs_linux.py” suggests the threat actor is also targeting Linux environments.

- Advertisement -

The extension parses a configuration file to extract C2 information and activate automated data harvesting, while a companion content script is embedded across all active web pages. SOCRadar identified references to “Authorized CTF” use, possibly to lower AI tool safety guardrails for malware development. The “/health” endpoint shows 34 agent entries, 10 active sessions, and 507 data records, though test entries cannot be distinguished from actual infections.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

UK FCA may lift ban on prediction markets for retail

The UK's Financial Conduct Authority is reportedly weighing whether to lift its 2019 ban...

Starcloud mining Bitcoin in space is a really crazy $2B idea

Starcloud, a data centers-in-space startup, raised nearly $500 million at a $2 billion valuation...

EIP-8141 Frames: Pay Gas in Tokens on Ethereum

EIP-8141's Frame transactions split a transaction into validation, payment and execution steps, each an...

Zcash ETF launch sparks rally to 2016 high

ZCash (ZEC) surged to $1,249.28, its highest price since 2016, pushing market cap above...

JSCeal Malware Steals Crypto via Compiled V8 Bytecode

Cybersecurity researchers have unveiled JSCeal, a sophisticated compiled V8 JavaScript malware used to steal...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading