{"id":2730,"date":"2026-09-07T18:47:30","date_gmt":"2026-09-07T18:47:30","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2730"},"modified":"2026-09-07T18:47:30","modified_gmt":"2026-09-07T18:47:30","slug":"peep-turns-chrome-and-edge-into-post-compromise-backdoors-for-host-command-execution","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2730","title":{"rendered":"PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhA3-5bNylOMc_s8MAT2ibQnV33cnJXadwKPRXjYgAL0GcZWOXuwtM-s5HS4ryVu5ewnhfAqBtOiuSseLcUSyDIfxf5XKF6mAwrpyG-v3Y-siqjJY8I5zVEMXwfkKPwBNAqaO2sQFI-q2oA4MWiagZFUlknIPKADDfvOo8s2Ifsa_xBAojg1rD5ZGUErC85\/s1700-nu-rw-lo-l85-e365\/chrome-malware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called <strong>PEEP<\/strong> that masquerades as a bookmarks extension for the web browser.<\/p>\n<p>\u00abRequiring prior administrative or code execution access, its installer injects the extension directly into Chrome\/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium&#8217;s own Secure Preferences integrity values,\u00bb SOCRadar <a href=\"https:\/\/socradar.io\/blog\/peep-browser-rat-chrome-extension\/\" target=\"_blank\">said<\/a>. \u00abA native-messaging tool then extends it beyond browser telemetry to host-level command execution and file management.\u00bb<\/p>\n<p>Once installed, the PEEP \u00abextension\u00bb agent polls its command-and-control (C2) server (\u00ab206.237.30[.]232\u00bb or \u00ab<a href=\"https:\/\/www.virustotal.com\/gui\/domain\/xfjcc.fun\/details\" target=\"_blank\">xfjcc[.]fun<\/a>\u00ab) every 30 seconds over plaintext HTTP for new commands, while exfiltrating browsing history, active-tab metadata, and session cookies. It also functions as a remote access and browser monitoring toolkit that runs host commands, steals credentials, hijacks sessions, and alters web pages.<\/p>\n<p>PEEP is built on the foundations of an open-source, browser data analysis and red teaming framework called RedExt, which has also been put to use in prior GlassWorm attacks. However, it expands on the toolkit with dedicated installation routines, a native host bridge, heartbeat telemetry, an update channel, and a broader command set. This, in turn, makes PEEP a derivative of RedExt.<\/p>\n<p>PEEP is described as a post-compromise framework as it lacks an initial access vector itself, meaning it requires the operator to breach a machine through some other means and deploy the malware. The activity remains unattributed, although the presence of Chinese-language artifacts in the source code points to a Chinese-speaking threat actor.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The extension masquerades as \u00abSmart Bookmarks\u00bb (ID: ejkndncpkdcjcikfhiamcdehdoegilbj). It&#8217;s the main agent responsible for executing the beacon loop by polling \u00ab\/api\/commands,\u00bb harvesting browser data, receiving additional tasking, and sending the results back.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The browser add-on also invokes an auxiliary executable (\u00abnm_host.exe\u00bb) when said task requires operating system access, while browser-based commands (e.g., screenshots, clipboard, or JavaScript injection) are run locally. The use of the <a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/develop\/concepts\/native-messaging\" target=\"_blank\">Native Messaging Host binary<\/a> transforms the malware from a basic credential stealer to a remote-access tool.<\/p>\n<p>\u00abOperating in the user context, the extension extracts browser artifacts and uses com.peep.lab\/nm_host.exe to run shell commands, manage files, and discover processes and services,\u00bb SOCRadar said. \u00abBypassing Web Store checks, PEEP maintains persistence via sideloading, enterprise force-install policies, preference-integrity manipulation, and a ScriptCache fallback.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhc9nsOJtcS9-FkHAK8Q79dhjarvivTCOa4HDAtp_OnqP2QlFx0KZIHrYH4HW-p8JNwd6MzSHi6IXRKvGbqvSaxsW0RfQ4wA0KvS6mLuPnDpHbnpfOkHIYiFayUpp3lUNZcaauJmpkeecrfzm4qZG4wx_Gjj5hXuMD2mXKnR-CMDvHXcYpd01yO3i8_Shad\/s1700-nu-rw-lo-l85-e365\/soc.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhc9nsOJtcS9-FkHAK8Q79dhjarvivTCOa4HDAtp_OnqP2QlFx0KZIHrYH4HW-p8JNwd6MzSHi6IXRKvGbqvSaxsW0RfQ4wA0KvS6mLuPnDpHbnpfOkHIYiFayUpp3lUNZcaauJmpkeecrfzm4qZG4wx_Gjj5hXuMD2mXKnR-CMDvHXcYpd01yO3i8_Shad\/s1700-nu-rw-lo-l85-e365\/soc.jpg\" alt=\"\" border=\"0\" data-original-height=\"1065\" data-original-width=\"1903\"\/><\/a><\/div>\n<p>Also used by the extension are several other endpoints &#8211;<\/p>\n<ul>\n<li>\u00ab\/api\/register\u00bb to register the infection<\/li>\n<li>\u00ab\/api\/agents\/<id>\/heartbeat\u00bb to send details about the browser&#8217;s User-Agent string, operating system, and time zone<\/id><\/li>\n<li>\u00ab\/api\/extension_update\/\u00bb and \u00ab\/api\/extension_crx\/\u00bb to update the extension itself<\/li>\n<li>\u00ab\/api\/agents\/<id>\/task_result\u00bb to post the results of the command execution<\/id><\/li>\n<li>\u00ab\/api\/exfil\u00bb to post auto-collected data, such as cookies, recent history, open tabs, active URL, public IP address, locale, and time zone<\/li>\n<li>\u00ab\/health\u00bb to serve internal system status without requiring login credentials<\/li>\n<li>\u00ab\/login\u00bb to serve a login interface for the C2 panel at port 5001<\/li>\n<\/ul>\n<p>Another defining aspect of PEEP is its ability to modify the Secure Preferences file to ensure that the extension is auto-enabled upon launching the browser. Given that the extension is not available on the Chrome Web Store and other official extension marketplaces, it also leverages the ExtensionInstallForcelist or ExtensionSettings policies and sideloading tricks for delivery.<\/p>\n<p>To aid in this tampering, the malware makes use of two PowerShell scripts &#8211;<\/p>\n<ul>\n<li>install_silent.ps1, which enables Developer Mode to sideload arbitrary extensions<\/li>\n<li>patch_secure_prefs.ps1, which patches the Secure Preferences file<\/li>\n<li>force_enable.ps1, which removes the extension from Preferences\u2019s external_uninstalls, places the CRX at %LOCALAPPDATA%PEEPcrx, re-registers via the HKCU Extensions key and an External Extensions JSON manifest, and restarts the browser<\/li>\n<\/ul>\n<p>There also exists a Python script \u00abpatch_secure_prefs_linux.py\u00bb indicating that the threat actor behind the operation is replicating the behavior to also target Linux environments.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Once initialized, the extension parses a configuration file to extract C2 information and activate automated data harvesting, while a companion content script (\u00abcontent.js\u00bb) is embedded across all active web pages.<\/p>\n<p>SOCRadar said it identified a number of references to \u00abAuthorized CTF\u00bb use, raising the possibility that the threat actor may have used the framing to lower the safety guardrails of AI tools and assist in malware development. There are currently no signs as to who is being targeted, but the \u00ab\/health\u00bb endpoint shows 34 agent entries, 10 active sessions, and 507 data records. That said, there is no way to differentiate actual infected hosts from test entries or verified deployments.<\/p>\n<p>\u00abPEEP builds on existing host compromises, using a native-messaging bridge to convert Chrome\/Edge into a persistent backdoor that crosses the browser sandbox to reach the OS,\u00bb SOCRadar said. \u00abBecause its logic runs inside the signed browser process, it slips past detection of keys on new or unsigned binaries. Consequently, the browser acts as an endpoint pivot for credential theft, session abuse, and command execution.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. \u00abRequiring prior administrative or code execution access,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2731,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[104,182,1223,568,13,1109,3333,3334,521],"class_list":["post-2730","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoors","tag-chrome","tag-command","tag-edge","tag-execution","tag-host","tag-peep","tag-postcompromise","tag-turns"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2730","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2730"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2730\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2731"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2730"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2730"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2730"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}