CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

September 7, 2026

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution Ravie LakshmananSep 07, 2026Malware / Browser Security Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences integrity values," SOCRadar said. "A native-messaging tool then extends it beyond browser telemetry to host-level command execution and file management." Once installed, the PEEP "extension" agent polls its command-and-control (C2) server ("206.237.30[.]232" or "xfjcc[.]fun") every 30 seconds over plaintext HTTP for new commands, while exfiltrating browsing history, active-tab metadata,…