Back Gbhackers Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands
A newly identified Chromium-based post-exploitation toolkit named PEEP can turn Google Chrome and Microsoft Edge into persistent remote-access platforms, enabling attackers to steal browser data, hijack sessions, manage files and execute shell commands on compromised endpoints.
Unlike a conventional initial-access malware strain, PEEP requires attackers to already possess administrative privileges or code-execution access on a target machine.
Once installed, however, it establishes long-term browser persistence and extends its reach from the browser into the operating system through Chrome Native Messaging.
PEEP is a modular browser RAT derived from the open-source RedExt framework, a Manifest V3 extension and Flask-based command-and-control architecture originally presented for authorized red-team operations.
RedExt supports browser collection functions including cookie extraction , browsing-history collection, screenshots, clipboard capture, DOM snapshots, local-storage harvesting and browser reconnaissance.
PEEP expands that model into a more operational post-exploitation toolkit.
The malicious extension runs as a Chrome or Edge service worker, communicates with a remote Flask-and-SQLite control panel, and routinely gathers browser telemetry.
Its operators can reportedly collect session cookies, browsing history, open-tab details, bookmarks, downloads, DOM content, local and session storage, clipboard data, screenshots and form fields.
The extension requests broad permissions, including access to cookies, tabs, history, downloads, scripting, proxy settings, native messaging and all HTTP and HTTPS origins.
This gives the malware visibility across most web activity performed under the compromised browser profile.
Critically, PEEP does not directly extract Chrome’s stored-password database.
The Threat Research Unit (STRU) at SOCRadar discovered PEEP masquerading as a benign Chrome extension called “Smart Bookmarks.”
Instead, it can capture password-like fields from web forms and steal session cookies, potentially allowing attackers to reuse authenticated sessions even when passwords are protected by multifactor authentication.
PEEP Chrome Extension
The most serious capability is PEEP’s native-messaging bridge. The extension communicates with a companion executable, nm_host.exe , registered as com.peep.lab , which enables browser-originated tasks to run outside Chromium’s sandbox.
The PE header TimeDateStamp of July 2022 stems from the base pkg Node image and does not reflect the actual build date.
Through this component, threat actors can execute shell commands, enumerate running processes and services, list directories, read and write files, for sensitive documents, create folders, rename files, calculate hashes and delete paths.
The activity still operates in the compromised user’s security context, so it does not inherently provide privilege escalation.
However, it converts a browser extension into a practical endpoint pivot for surveillance, credential theft and host-level control.
The agent reportedly contacts its command server every 30 seconds over unencrypted HTTP, registering the infected browser, polling for tasks and returning collected data or command output.
The use of plaintext HTTP creates an additional exposure: network defenders may be able to identify suspicious request patterns, headers and C2 traffic if they have adequate proxy, DNS or network telemetry.
PEEP uses several persistence mechanisms designed to keep the extension active without a normal Chrome Web Store installation.
Its delivery scripts can manipulate Chromium’s Secure Preferences integrity values, including per-entry HMAC protections and the top-level super_mac , making modified extension settings appear legitimate to the browser.
The toolkit can also use enterprise force-install policy settings, external sideloading and a ScriptCache fallback technique.
The latter can preserve a compiled malicious Manifest V3 service worker even after visible extension files have been replaced with benign-looking content, complicating manual review.
SOCRadar reported that the PEEP infrastructure used the hardcoded IP address 206.237.30[.]232 , associated with Cloudie Limited in Hong Kong.
The same host allegedly handled C2 activity, payload distribution and an exposed development repository on TCP port 5002.
Researchers found source code, builds, logs, utilities and the private key associated with the primary extension identity in the exposed directory.
Defenders should review Chrome and Edge extension inventories for the “Smart Bookmarks” name and suspicious extension IDs, particularly ejkndncpkdcjcikfhiamcdehdoegilbj and bibjjhidpdmfcbkodddndmoejcloobdh .
Security teams should also inspect Native Messaging host registrations for com.peep.lab , including Chrome and Edge NativeMessagingHosts registry paths.
Network teams can hunt for HTTP connections to 206.237.30[.]232 , the domain xfjcc[.]fun , and recurring 30-second beaconing patterns.
Endpoint defenders should investigate unexpected PowerShell activity modifying Chrome preferences, enterprise extension policies, external extension registrations or files under browser profile directories.
PEEP shows how browser extensions can become a durable post-compromise foothold.
Rather than relying on a separate unsigned RAT binary, attackers can hide operational logic inside a trusted browser process, blend into routine web activity and use native messaging to break beyond the browser sandbox.
Indicators of Compromise (IOCs)
Note: IP addresses and domains are intentionally defanged (e.g., [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026 .
Artificial Intelligence
Cyber security Course
Cyber Security Resources
Cybersecurity
Information Gathering
Information Security Risks
Hackers Actively Exploiting MikroTik RouterOS MikroTrick Flaws to Take Full Control of Routers
CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security
Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
