$ techbeacon▋
CVE & Exploits

New Chromium-Based Toolkit ‘PEEP’ Turns Browsers Into Stealthy Command Execution Backdoors

New Chromium-Based Toolkit ‘PEEP’ Turns Browsers Into Stealthy Command Execution Backdoors

Cybersecurity researchers have detailed a sophisticated post‑exploitation framework called PEEP that covertly transforms popular browsers such as Google Chrome and Microsoft Edge into command‑execution backdoors. The toolkit masquerades as a benign bookmarks extension, allowing threat actors to issue system‑level commands on compromised machines while remaining hidden behind a familiar browser feature.

PEEP’s operation begins with the attacker already possessing administrative privileges or having achieved an initial code‑execution foothold on the target system. From that point, the toolkit’s installer injects the malicious extension into the browser’s extension store, leveraging Chromium’s extension architecture to establish a persistent communication channel with a remote command‑and‑control server. Once installed, the extension can execute arbitrary shell commands, retrieve system information, and facilitate further lateral movement without raising immediate alerts.

The use of a bookmarks extension is a calculated evasion technique. Browser extensions are routinely granted elevated permissions to interact with web content and, in many enterprise environments, are whitelisted for convenience. By presenting itself as a legitimate utility for managing bookmarks, PEEP blends into normal user activity, complicating detection by both automated security tools and manual reviewers. This approach follows a broader trend where attackers weaponize trusted software components to maintain stealth.

Given that Chrome and Edge together command a majority share of the desktop browser market, the potential impact of PEEP is significant. Organizations that allow users to install extensions without strict oversight may inadvertently provide a foothold for malicious actors. Security teams are advised to monitor extension installation logs, enforce the principle of least privilege for browser processes, and consider employing application control solutions that can block unsigned or unknown extensions.

The findings were first reported by The Hacker News, prompting calls for browser vendors to tighten extension vetting processes and for security vendors to develop detection signatures targeting PEEP’s distinctive behaviors. Researchers stress that timely patching, regular audits of installed extensions, and user education about the risks of unknown browser add‑ons are essential steps to mitigate this emerging threat vector.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related