PEEP Browser RAT Poses as 'Smart Bookmarks' Chrome Extension, Turning Chrome and Edge Into Host-Level Backdoors
SOCRadar's Threat Research Unit (STRU) identified PEEP, a Chromium-based post-exploitation RAT disguised as a legitimate 'Smart Bookmarks' Chrome extension. It is injected directly into Chrome and Edge profiles by forging Secure Preferences integrity values,…
PEEP is a Chromium-based post-exploitation toolkit that provides RAT-style remote access while posing as a legitimate browser extension. SOCRadar's STRU first flagged and analyzed it as an emerging threat requiring monitoring on 2026-09-04. Further technical details, reported on 2026-09-07, show that PEEP masquerades as a 'Smart Bookmarks' extension and is injected directly into Chrome and Edge profiles by forging Secure Preferences integrity values, bypassing Web Store checks. A native-messaging host binary (nm_host.exe) bridges the browser agent to the operating system, enabling host-level command execution, file management, credential theft, session hijacking, and persistence. The extension polls C2 endpoints at 206.237.30.232 or the domain xfjcc.fun every 30 seconds over plaintext HTTP and exfiltrates browsing history, cookies, tab metadata, and session data. PEEP is derived from the open-source RedExt red teaming framework, which has also been used in GlassWorm attacks, and adds PowerShell persistence scripts plus a Linux-targeting Python script, suggesting cross-platform intent. The activity is unattributed, but Chinese-language artifacts suggest a Chinese-speaking operator. A C2 /health endpoint showed 34 agent entries and 10 active agents. The two reports do not conflict; the later report substantially expands the initial analysis with technical specifics.
- PEEP is a Chromium-based post-exploitation toolkit delivering RAT-style remote access while posing as a legitimate Chrome extension (SOCRadar STRU, 2026-09-04).
- It masquerades as a 'Smart Bookmarks' extension and is injected directly into Chrome and Edge profiles by forging Secure Preferences integrity values, bypassing Web Store checks (2026-09-07 report).
- The native-messaging host binary nm_host.exe extends the browser agent to host-level OS command execution, file management, credential theft, session hijacking, and persistence.
- The extension polls C2 endpoints at 206.237.30.232 or xfjcc.fun every 30 seconds over plaintext HTTP.
- Exfiltrated data includes browsing history, cookies, tab metadata, and session data.
- PEEP is derived from the open-source RedExt red teaming framework, which has also been used in GlassWorm attacks.
- It adds PowerShell persistence scripts and includes a Linux-targeting Python script, suggesting cross-platform intent.
- The activity is unattributed, but Chinese-language artifacts suggest a Chinese-speaking operator.
Coverage timelineoldest first · each row is one article
- · 12d agoPEEP: A Browser RAT Posing as a Chrome Extension
SOCRadar· 45
SOCRadar's STRU analyzed PEEP, an emerging Chromium-based RAT disguised as a Chrome extension enabling post-exploitation control of browsers.