Malicious Chrome Extension "PEEP" Turns Browsers into Backdoors for Cyberattackers
Security researchers at SOCRadar have uncovered PEEP, a malicious Chromium-based extension disguised as Smart Bookmarks (v1.3.0) that transforms compromised Windows systems into remote backdoors. Derived from the open-source RedExt project, PEEP operates as a post-compromise toolkit, requiring prior access to a device such as through malware or administrative privileges to install silently in Chrome or Edge.
Once deployed, the extension bypasses standard security checks by altering browser settings, enabling it to launch without user approval or visible warnings. PEEP’s capabilities extend far beyond typical data theft, leveraging native-messaging bridges to execute shell commands, manipulate files, and enumerate running processes effectively granting attackers host-level control from within the browser.
Key Threat Features
- Session Hijacking: Steals active login cookies, allowing attackers to bypass passwords and multi-factor authentication (MFA) by reusing valid sessions until revoked.
- Comprehensive Data Collection: Harvests browsing history, open tabs, form inputs, clipboard contents, screenshots, and local/session storage.
- Command Execution: Injects JavaScript, modifies proxy settings, and captures page content via unencrypted HTTP communication with its command-and-control (C2) server.
- Persistence Mechanisms: Uses forged Chrome Secure Preferences, enterprise policies, and ScriptCache fallbacks to evade removal, complicating cleanup efforts.
Infrastructure & Indicators
PEEP’s C2 infrastructure includes the IP 206.237.30.232 and domains like xfjcc[.]fun, with exposed endpoints for agent registration, command polling, and data exfiltration. Researchers identified multiple extension IDs (e.g., ejkndncpkdcjcikfhiamcdehdoegilbj) and artifacts, including a native-messaging host (com.peep.lab) and scripts for silent installation (install_silent.ps1).
While the exact scale of infections remains unclear with a server snapshot showing 34 agent entries and 507 data records the toolkit’s design poses significant risks, particularly for organizations where stolen sessions could grant unauthorized access to sensitive accounts.
Defensive Considerations
The discovery follows prior incidents where malicious extensions exploited native-messaging hosts to escalate browser-based attacks into full system compromise. Defenders are advised to block identified IoCs, scrutinize browser policies, and treat PEEP infections as both endpoint and identity incidents, including session revocation and credential rotation.
The incident underscores the growing threat of post-compromise toolkits that abuse legitimate browser functionality to maintain persistence and evade detection.
Source: https://cybersecuritynews.com/malicious-chrome-extension-2/
Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security
"id": "mic1788776702",
"linkid": "microsoft-security",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'type': 'Organizations/Individuals'}],
'attack_vector': 'Malicious Chrome/Edge extension (post-compromise toolkit)',
'data_breach': {'data_exfiltration': 'Yes (via C2 server communication)',
'number_of_records_exposed': '507 data records (server '
'snapshot)',
'personally_identifiable_information': 'Potential (via '
'session hijacking)',
'sensitivity_of_data': 'High (active login sessions, PII '
'potential)',
'type_of_data_compromised': 'Browsing history, session '
'cookies, form inputs, clipboard '
'data, screenshots, local/session '
'storage'},
'description': 'Security researchers at SOCRadar have uncovered PEEP, a '
'malicious Chromium-based extension disguised as Smart '
'Bookmarks (v1.3.0) that transforms compromised Windows '
'systems into remote backdoors. Derived from the open-source '
'RedExt project, PEEP operates as a post-compromise toolkit, '
'requiring prior access to a device to install silently in '
'Chrome or Edge. The extension bypasses security checks, '
'enabling attackers to execute shell commands, manipulate '
'files, and enumerate processes, granting host-level control '
'from within the browser.',
'impact': {'data_compromised': 'Browsing history, open tabs, form inputs, '
'clipboard contents, screenshots, '
'local/session storage, active login cookies',
'identity_theft_risk': 'High (session hijacking, MFA bypass)',
'operational_impact': 'Unauthorized access to sensitive accounts '
'via session hijacking, potential system '
'compromise',
'systems_affected': 'Windows systems with Chrome or Edge browsers'},
'initial_access_broker': {'backdoors_established': 'Native-messaging host '
'(com.peep.lab), forged '
'preferences, enterprise '
'policies',
'entry_point': 'Prior malware infection or '
'administrative access'},
'lessons_learned': 'The incident underscores the growing threat of '
'post-compromise toolkits that abuse legitimate browser '
'functionality to maintain persistence and evade '
'detection.',
'post_incident_analysis': {'corrective_actions': 'Enhanced browser policy '
'monitoring, session '
'management controls, IoC '
'blocking, credential '
'rotation',
'root_causes': 'Abuse of native-messaging bridges, '
'lack of browser policy scrutiny, '
'post-compromise toolkit '
'deployment'},
'recommendations': 'Block identified IoCs, scrutinize browser policies, treat '
'PEEP infections as both endpoint and identity incidents, '
'revoke sessions, rotate credentials, and monitor for '
'unauthorized access.',
'references': [{'source': 'SOCRadar'}],
'response': {'containment_measures': 'Block identified IoCs, scrutinize '
'browser policies, session revocation, '
'credential rotation',
'third_party_assistance': 'SOCRadar (security researchers)'},
'title': "Malicious Chrome Extension 'PEEP' Turns Browsers into Backdoors for "
'Cyberattackers',
'type': 'Malicious Browser Extension',
'vulnerability_exploited': 'Native-messaging bridges, forged Chrome Secure '
'Preferences, enterprise policies'}