Thehackernews
PEEP Chrome Extension Turns Browsers Into Remote Access Tools
Article Content
Cybersecurity researchers have uncovered a sophisticated post-exploitation toolkit named PEEP, which masquerades as a 'Smart Bookmarks' Chrome extension. This malware requires prior administrative access to be installed, allowing it to bypass Web Store checks and inject itself directly into Chrome and Edge profiles. Once installed, PEEP can steal browser data, hijack sessions, and execute shell commands on compromised machines. It communicates with a command-and-control server every 30 seconds, exfiltrating sensitive data such as browsing history and session cookies. The toolkit is derived from the open-source RedExt framework and shows signs of being linked to a Chinese-speaking threat actor. PEEP's capabilities include remote command execution and file management, making it a significant threat to users of affected browsers. Current reports indicate that this malware is actively being exploited in the wild.
Key Points: • PEEP masquerades as a benign Chrome extension to gain unauthorized access. • It requires prior administrative privileges for installation, making it a post-compromise tool. • The malware is linked to a Chinese-speaking threat actor and actively exfiltrates sensitive data.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.