PEEP Chrome Extension Turns Browsers Into Remote Access Tools

PEEP Chrome Extension Turns Browsers Into Remote Access Tools

First seen 7 Sep 2026, 19:03 UTC Gbhackersunderdefense.comThehackernewsGround.Newscybernoz.com+4 75.8

Article Content

Browse articles
ThreatCluster

Cybersecurity researchers have uncovered a sophisticated post-exploitation toolkit named PEEP, which masquerades as a 'Smart Bookmarks' Chrome extension. This malware requires prior administrative access to be installed, allowing it to bypass Web Store checks and inject itself directly into Chrome and Edge profiles. Once installed, PEEP can steal browser data, hijack sessions, and execute shell commands on compromised machines. It communicates with a command-and-control server every 30 seconds, exfiltrating sensitive data such as browsing history and session cookies. The toolkit is derived from the open-source RedExt framework and shows signs of being linked to a Chinese-speaking threat actor. PEEP's capabilities include remote command execution and file management, making it a significant threat to users of affected browsers. Current reports indicate that this malware is actively being exploited in the wild.

Key Points: • PEEP masquerades as a benign Chrome extension to gain unauthorized access. • It requires prior administrative privileges for installation, making it a post-compromise tool. • The malware is linked to a Chinese-speaking threat actor and actively exfiltrates sensitive data.

Ask AI about this cluster

Timeline

2026-09-04
CVE-2026-75754 published
A vulnerability related to the PEEP toolkit was published, detailing its exploitation methods.
Gbhackers
2026-09-07
PEEP toolkit disclosed
Researchers at SOCRadar disclosed details about the PEEP toolkit, highlighting its capabilities and installation methods.
Thehackernews
2026-09-08
PEEP toolkit analysis published
Further analysis of the PEEP toolkit was published, confirming its malicious functionalities and links to prior attacks.
cybernoz.com