PEEP Turns Chrome and Edge into Post-Compromise Backdoors

PEEP is a new post-compromise toolkit that turns Chrome and Edge into backdoors, evading detection by operating inside the browser's trusted environment.

By Central
PEEP masquerades as a harmless bookmark extension while secretly exfiltrating data and executing commands.
Highlights
  • PEEP operates entirely within the browser's trusted process environment, evading detection mechanisms that monitor for unknown binaries.
  • The malware uses a native-messaging bridge to extend its reach beyond browser telemetry to host-level command execution.
  • As of analysis, the C2 panel showed 34 agent entries and 10 active sessions, indicating a contained but active operation.

A newly identified post-exploitation toolkit is transforming Google Chrome and Microsoft Edge browsers into fully operational backdoors, granting attackers persistent remote access to compromised systems. Dubbed PEEP by researchers at SOCRadar, this sophisticated Chromium-based malware masquerades as a harmless bookmark extension while secretly exfiltrating data, executing system commands, and manipulating web content. What makes PEEP particularly dangerous is that it operates entirely within the browser’s trusted process environment, evading detection mechanisms that monitor for unknown or unsigned binaries.

What Is PEEP and How Does It Turn Browsers into Backdoors?

PEEP is a post-compromise framework that requires an attacker to have already gained administrative or code execution access to a target system. Once deployed, it injects a malicious browser extension directly into Chrome or Edge user profiles, bypassing the official Chrome Web Store and all user prompts. The extension masquerades under the name “Smart Bookmarks” with the identifier ejkndncpkdcjcikfhiamcdehdoegilbj. It polls its command-and-control (C2) server every 30 seconds over plaintext HTTP to receive new instructions, while simultaneously exfiltrating browsing history, active-tab metadata, and session cookies. Through a native-messaging bridge, PEEP extends its reach beyond browser telemetry to host-level command execution and file management, effectively converting the browser into a persistent remote access tool.

Technical Deep Dive: The Extension, Native Messaging, and C2 Infrastructure

The Browser Extension Core

The PEEP extension is the main agent responsible for the beacon loop. It regularly contacts the endpoint /api/commands on its C2 server to retrieve new tasks. The known C2 servers are 206.237.30[.]232 and xfjcc[.]fun. Beyond command retrieval, the extension harvests extensive browser data and sends results back via several API endpoints:

  • /api/register – registers the infection with the C2 panel.
  • /api/agents/[id]/heartbeat – sends browser User-Agent string, operating system details, and time zone.
  • /api/agents/[id]/task_result – posts the results of executed commands.
  • /api/exfil – pushes auto-collected data including cookies, recent history, open tabs, active URL, public IP address, locale, and time zone.
  • /api/extension_update/ and /api/extension_crx/ – allow the extension to update itself.
  • /health – serves internal system status without requiring login credentials.
  • /login – provides a login interface for the C2 panel at port 5001.

The extension also embeds a companion content script (content.js) across all active web pages, enabling real-time page modification and clipboard access.

The Native-Messaging Bridge

When a task requires operating system access — such as running shell commands, managing files, or discovering processes and services — the extension invokes an auxiliary executable named nm_host.exe. This binary acts as a native-messaging host, a legitimate Chrome API that allows extensions to communicate with native applications. By using this bridge, PEEP transcends the browser sandbox and operates with the privileges of the user context. Browser-based commands like screenshots, clipboard access, or JavaScript injection are executed locally within the extension itself.

Derivative of the RedExt Framework

PEEP is built on the foundations of RedExt, an open-source browser data analysis and red teaming framework that was previously used in GlassWorm attacks. However, PEEP expands significantly on RedExt by adding dedicated installation routines, a native host bridge, heartbeat telemetry, an update channel, and a broader command set. This evolution transforms a red team tool into a full-fledged malware platform.

Persistence and Installation: Bypassing Web Store Security

Tampering with Chrome’s Secure Preferences

One of PEEP’s most notable technical achievements is its ability to modify the browser’s Secure Preferences file. This file is cryptographically signed by Chromium to prevent tampering. The malware forges these integrity values to ensure the malicious extension is auto-enabled upon every browser launch. This is achieved through a PowerShell script called patch_secure_prefs.ps1, which directly patches the preferences file without triggering integrity warnings.

Sideloading and Enterprise Policies

Since the extension does not appear in any official store, attackers rely on alternative installation methods:

  • install_silent.ps1 – enables Developer Mode to sideload arbitrary extensions.
  • force_enable.ps1 – removes the extension from the Preferences external_uninstalls list, places the CRX file at %LOCALAPPDATA%\PEEP\crx, re-registers via the HKCU Extensions key and an External Extensions JSON manifest, and then restarts the browser.

Additionally, the malware can leverage the ExtensionInstallForcelist or ExtensionSettings group policies, and uses a ScriptCache fallback mechanism to ensure persistence even if the extension is manually removed.

Linux Targeting

A Python script named patch_secure_prefs_linux.py was also discovered, indicating the threat actor is replicating the same behavior for Linux environments. This cross-platform ambition increases the potential scope of future infections.

Current Threat Landscape: Limited but Active Infections

As of the time of analysis, the /health endpoint showed 34 agent entries, 10 active sessions, and 507 data records. It is impossible to distinguish real infected hosts from test entries or verified deployments, but the numbers suggest a contained but active operation. The threat actor remains unclaimed, though the presence of Chinese-language artifacts in the source code points to a Chinese-speaking group. Researchers also noted references to “Authorized CTF” use, possibly a deliberate framing to bypass AI safety guardrails during malware development.

Strategic Implications: The Browser as an Endpoint Pivot

PEEP exemplifies a growing trend in post-compromise tooling: using trusted, signed browser processes as a cover for malicious activity. Because the extension’s logic runs inside the browser — a signed and frequently whitelisted executable — it slips past many endpoint detection and response systems that focus on new or unsigned binaries. The browser becomes an endpoint pivot for credential theft, session hijacking, and command execution. As defenses improve against traditional malware, threat actors are increasingly turning to living-off-the-land techniques that abuse legitimate platform features. Organizations must therefore extend their security monitoring to include browser extension behavior, native-messaging hosts, and integrity checks on user profile preferences. The sophistication of PEEP underscores that even a fully patched browser can become a dangerous weapon when the attacker already controls the machine.

Share This Article