New Chrome Extension Turns Browsers Into Stealthy Remote‑Access Tools, Researchers Warn
A security researcher has uncovered a covert post‑exploitation framework called PEEP that repurposes the Google Chrome and Microsoft Edge browsers into persistent footholds for attackers. By leveraging a seemingly innocuous extension, the toolkit can harvest saved passwords, hijack active sessions, manipulate files, and even run arbitrary shell commands on the infected machine.
PEEP operates by installing a custom extension in Chromium‑based browsers, which then establishes a covert channel to a remote command‑and‑control server. Once in place, the malicious code can persist across browser restarts and system reboots, giving threat actors long‑term access without requiring additional malware binaries.
The discovery, first reported by the cybersecurity community GBHackers, highlights a growing trend of abusing legitimate browser extensions for malicious ends. Because extensions are granted extensive privileges by default—such as reading browsing history and interacting with web pages—they present an attractive vector for post‑exploitation activities once a system has already been compromised.
Experts note that the toolkit’s ability to execute shell commands directly from the browser is particularly concerning. This capability bypasses many traditional endpoint defenses that focus on monitoring executable files, allowing attackers to manipulate the operating system, install additional payloads, or exfiltrate data stealthily.
While the exact number of affected users remains unknown, the researchers stress that any organization or individual using Chrome or Edge should audit installed extensions and verify their provenance. Disabling unnecessary extensions, enforcing strict extension policies, and keeping browsers up to date are among the recommended mitigations.
Security teams are advised to monitor network traffic for unusual communication patterns associated with browser extensions and to employ endpoint detection tools that can flag atypical command‑execution behavior. As browser extensions continue to evolve, analysts anticipate that attackers will further refine techniques that blur the line between legitimate functionality and malicious control.
Comments (0)
Be the first to comment.
Join the discussion