Zero Day Room
Live
Threats

PEEP Malware Turns Chrome and Edge into Post-Compromise

A new post-exploitation toolkit called PEEP injects a malicious extension into Chrome and Edge browsers, allowing attackers to execute host commands and

A new post-exploitation toolkit called PEEP injects a malicious extension into Chrome and Edge browsers, allowing...

Cybersecurity firm SOCRadar has detailed a post-compromise framework named PEEP that turns Chromium-based browsers into backdoors for host command execution. The malware, which lacks its own initial access vector, must be deployed after a system is already breached.

PEEP masquerades as a "Smart Bookmarks" browser extension with the ID ejkndncpkdcjcikfhiamcdehdoegilbj. SOCRadar stated, "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks." Once installed, the extension agent polls its command-and-control server every 30 seconds over plaintext HTTP.

Malware Capabilities and Data Exfiltration

The extension functions as a remote access and monitoring toolkit. It exfiltrates browsing history, active-tab metadata, and session cookies. It can also run host commands, steal credentials, hijack sessions, and alter web pages. For tasks requiring operating system access, the add-on invokes an auxiliary executable called nm_host.exe. This native-messaging host binary transforms PEEP from a basic credential stealer into a full remote-access tool.

The malware uses several endpoints to communicate with its C2 server, located at 206.237.30[.]232 or xfjcc[.]fun.

Installation and Persistence Mechanisms

PEEP bypasses official browser stores through sideloading and enterprise force-install policies. It maintains persistence by manipulating Chromium's Secure Preferences file to auto-enable the extension on browser launch. The malware uses a series of PowerShell scripts to aid its installation and tampering.

The scripts include install_silent.ps1 to enable Developer Mode for sideloading, patch_secure_prefs.ps1 to patch the Secure Preferences file, and force_enable.ps1 to re-register the extension and restart the browser. Researchers also found a Python script named patch_secure_prefs_linux.py, indicating efforts to replicate the behavior for Linux environments.

Origins and Targeting

The toolkit is built on the open-source RedExt framework, previously used in GlassWorm attacks. PEEP expands on it with dedicated installation routines, a native host bridge, and a broader command set. The activity remains unattributed, but Chinese-language artifacts in the source code point to a Chinese-speaking threat actor.

SOCRadar identified references to "Authorized CTF" use, suggesting the threat actor may have used this framing to lower safety guardrails of AI tools during development. The /health endpoint showed 34 agent entries, 10 active sessions, and 507 data records, though these could be test entries. There are no clear signs of who is being targeted.

SOCRadar concluded that PEEP builds on existing host compromises. "Because its logic runs inside the signed browser process, it slips past detection of keys on new or unsigned binaries," the firm said. The browser thus becomes an endpoint pivot for credential theft, session abuse, and command execution.

Related coverage

More from Threats