Threat Intelligence

PEEP Malware Turns Chrome and Edge Into Backdoors on Already-Compromised Machines

The Hacker News · 8 Sept 2026
Key Takeaway Businesses should monitor for unauthorised or unfamiliar browser extensions and restrict administrative access, since PEEP relies on attackers already having a foothold on a device to install its fake bookmarks extension.

Security researchers at SOCRadar have detailed a sophisticated post-exploitation toolkit named PEEP that disguises itself as a browser extension called "Smart Bookmarks" for Google Chrome and Microsoft Edge. Unlike typical malicious extensions, PEEP does not rely on tricking users into installing it from an app store. Instead, it requires the attacker to already have administrative or code execution access on a machine, after which its installer forges internal Chromium security settings to inject itself directly into browser profiles, bypassing normal checks and prompts.

Once active, PEEP contacts a remote command-and-control server every 30 seconds over unencrypted web traffic, sending back browsing history, open tab details, and session cookies. It also pairs with a separate executable file that allows attackers to run commands directly on the infected computer, not just within the browser, effectively turning it into a full remote access tool capable of stealing credentials, hijacking sessions, and altering web pages. The malware is built on an open-source red-teaming framework called RedExt, previously seen in other attack campaigns, but PEEP adds new installation routines, update capabilities, and a wider range of remote commands.

Because PEEP requires a prior breach to be deployed, researchers describe it as a tool used after attackers have already gained a foothold, rather than an initial infection method. While the identity of those behind it remains unconfirmed, Chinese-language elements found in the code suggest a Chinese-speaking threat actor may be responsible.

browser security malware post-exploitation Chrome Edge

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.