Thehackernews
PEEP Chrome Extension Enables Credential Theft and Shell Command Execution
Article Content
A new post-exploitation toolkit named PEEP has been identified, affecting Google Chrome and Microsoft Edge. This toolkit masquerades as a benign bookmarks extension, requiring prior administrative or code execution access to install. Once active, PEEP can steal browser data, hijack sessions, and execute shell commands on compromised systems. It operates by injecting itself into browser profiles and bypassing Web Store checks. The toolkit communicates with a command-and-control server every 30 seconds, exfiltrating sensitive data like session cookies and browsing history. PEEP is derived from the RedExt framework and has capabilities for file management and command execution beyond the browser. The presence of Chinese-language artifacts in the code suggests a potential link to Chinese-speaking threat actors. SOCRadar discovered the toolkit, which has been reported but remains unattributed.
Key Points: • PEEP requires prior administrative access to install and operates as a browser extension. • The toolkit can steal sensitive data and execute commands outside the browser sandbox. • Chinese-language artifacts in the code hint at a potential link to Chinese-speaking threat actors.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.