PEEP Turns Chrome and Edge Into Stealthy Backdoors

SOCRadar disclosed PEEP, a post-compromise toolkit that turns Google Chrome and Microsoft Edge into a persistent control channel for host command execution, credential theft, session hijacking, and data exfiltration. It is not an initial-access bug: the operator must already have code execution or admin access before the installer injects a forged extension into the browser profile. PEEP forges Chromium Secure Preferences so the extension looks legitimately installed, then uses native messaging to hand browser activity off to a helper binary for OS-level commands and file handling. That means the payload can live inside signed browser processes, steal cookies and active-tab data, and keep running even when defenses are watching for suspicious executables rather than browser state. For Chrome- and Edge-heavy enterprises, the exposure sits in the browser profile and session layer, not just on disk or in the Web Store. If identity controls rely on browser cookies and logged-in tabs, a compromise that reaches the browser can preserve access after the password path is gone.

Part of the PlainSec briefing for 2026-09-08

Editions

Sources