← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

PEEP Toolkit Turns Chrome/Edge into Backdoors for Host Command Execution

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • PEEP is a Chromium-based post-exploitation toolkit.
  • It masquerades as a browser extension, bypassing Web Store checks.
  • PEEP enables host-level command execution and data exfiltration.
  • It is a derivative of the open-source RedExt framework.

PEEP: A New Post-Exploitation Toolkit

Cybersecurity researchers have uncovered PEEP, a sophisticated post-exploitation toolkit designed for Chromium-based browsers like Chrome and Edge. PEEP operates as a malicious browser extension, allowing attackers to gain control over compromised systems and exfiltrate data.

Installation and Functionality

PEEP's installer injects the extension directly into browser profiles, bypassing standard Web Store checks and user prompts by forging Chromium's Secure Preferences integrity values. Once installed, the extension, disguised as "Smart Bookmarks," polls a command-and-control (C2) server every 30 seconds for new commands. It exfiltrates browsing history, active-tab metadata, and session cookies.

A native-messaging tool extends PEEP's capabilities beyond browser telemetry to include host-level command execution and file management. This allows it to function as a remote access and browser monitoring toolkit, capable of running host commands, stealing credentials, hijacking sessions, and altering web pages.

Evolution from RedExt

PEEP is built upon the open-source browser data analysis and red teaming framework known as RedExt, which has been used in previous GlassWorm attacks. PEEP enhances RedExt with dedicated installation routines, a native host bridge, heartbeat telemetry, an update channel, and an expanded command set, making it a more advanced derivative.

Post-Compromise Requirement

PEEP is classified as a post-compromise framework because it lacks an initial access vector. This means an operator must first breach a machine through other means before deploying the malware. While the activity remains unattributed, the presence of Chinese-language artifacts in the source code suggests a Chinese-speaking threat actor.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~8 min · 6 stories · Sep 07

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers have detailed PEEP, a Chromium-based post-exploitation toolkit disguised as a browser extension that enables host-level command execution and data exfiltration. PEEP requires prior administrative access for installation and expands on the open-source RedExt framework, allowing attackers to control compromised machines and steal sensitive information.