thehackernews.com 7 Sept 2026, 18:12 UTC

PEEP Malware Hijacks Chrome and Edge to Steal Sessions and Run Commands

CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS have disclosed a Chromium-based post‑exploitation toolkit named PEEP that masquerades as a Chrome/Edge bookmarks extension. Described by SOCRadar, PEEP requires prior admin or code‑execution access and then injects a browser extension directly into user profiles, bypassing Web Store checks and user prompts by forging Chromium’s Secure Preferences integrity values. A native‑messaging component then extends the compromise from browser telemetry to host‑level command execution and file management.

Once active, PEEP polls its command‑and‑control server every 30 seconds over plaintext HTTP, retrieves tasks, and exfiltrates browser data such as history, active‑tab metadata and session cookies. The extension operates as a remote‑access and monitoring toolkit capable of running host commands, stealing credentials, hijacking sessions and altering web pages.

It also uses a two‑step approach to persistence: sideloading via enterprise policy settings and manipulation of Secure Preferences, plus a ScriptCache fallback. An auxiliary host binary, nm_host.exe, is invoked for operating system actions, with content scripts running on web pages to harvest data. Linux targets are implied via a patch‑secure‑prefs script in the toolkit’s distribution.

Current evidence from the reported infrastructure shows a health endpoint with 34 agent entries, 10 active sessions and 507 data records, though it remains unclear who is targeted. The activity suggests a Chinese‑speaking actor behind the operation, with PEEP building on RedExt foundations to enable browser‑pivoted backdoor capabilities across OSes.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline