Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Telerik Sitefinity RCE Flaw Lets Unauthenticated Attackers Take Over Servers
September 7, 2026
OpenVPN Patches 7 High-Severity Flaws Exposing VPN Connections
September 7, 2026
N-able Patches Critical RCE Vulnerability in N-central Platform
September 7, 2026
Home/Threats/New Chrome Extension Steals Login Sessions, Creates Backdoors
Threats

New Chrome Extension Steals Login Sessions, Creates Backdoors

Key Takeaways A new malicious Chrome extension, dubbed PEEP, can steal active login sessions and establish persistent backdoors on compromised Windows systems. PEEP masquerades as “Smart...

David kimber
David kimber
September 7, 2026 3 Min Read
3 0

Key Takeaways

  • A new malicious Chrome extension, dubbed PEEP, can steal active login sessions and establish persistent backdoors on compromised Windows systems.
  • PEEP masquerades as “Smart Bookmarks” and leverages an existing compromise to install silently on Chrome and Edge browsers.
  • The extension grants attackers extensive access to browser data, including cookies, history, and form data, and can execute commands on the host system via a native messaging bridge.
  • Its sophisticated persistence mechanisms make removal challenging, requiring more than just uninstalling the extension.
  • The threat highlights the severe risks posed by malicious browser add-ons, particularly those that gain operating system-level control.

A sophisticated malicious Chrome extension, identified as PEEP, has been uncovered, capable of exfiltrating active user login sessions and transforming an already compromised Windows machine into a remote backdoor. This discovery underscores the evolving danger posed by browser add-ons when they achieve elevated access to the underlying operating system.

The PEEP toolkit does not act as an initial access vector. Instead, it relies on adversaries having prior code execution capabilities or administrative privileges on a target system. Once these prerequisites are met, attackers can surreptitiously inject the extension into Chrome or Edge browser profiles. Its installation mechanisms are designed to bypass standard browser security checks, approval prompts, and visible warnings, ensuring a silent deployment. For a detailed analysis, refer to the SOCRadar report.

Security researchers at SOCRadar identified this operation, naming the toolkit PEEP. It is a Chromium-based post-compromise tool derived from the open-source RedExt project. SOCRadar said in a report that their investigation revealed a primary build of PEEP, disguised as “Smart Bookmarks” version 1.3.0, alongside a testing variant and an exposed development repository.

While the full extent of PEEP’s victim count remains undetermined, a snapshot from a command-and-control (C2) server indicated 34 agent entries, 10 active sessions, and 507 data records. However, these figures include test identifiers, preventing a precise count of actual compromised devices. Regardless, the design of PEEP poses a significant threat, as stolen session cookies can grant attackers unauthorized access to user accounts without requiring passwords or multi-factor authentication, until the sessions are explicitly revoked. This deep dive into PEEP’s capabilities is available in the SOCRadar’s full report.

Malicious Chrome Extension Capabilities

Upon activation, PEEP demands extensive permissions within the browser, requesting access to user tabs, cookies, browsing history, bookmarks, downloads, browser settings, scripting capabilities, and all websites. This broad access allows it to meticulously collect sensitive data including browsing history, details of open tabs, session cookies, form submissions, clipboard contents, screenshots, and both local and session storage data. This comprehensive data collection provides attackers with an in-depth view of a victim’s online activities, as detailed in the SOCRadar’s full report.

The ability to steal session cookies is particularly alarming because a valid cookie inherently verifies a user’s prior authentication. As documented in various security analyses, an attacker possessing such a token can hijack an active session, effectively bypassing subsequent password or multi-factor authentication requirements until the session is invalidated. PEEP also features command-and-control (C2) capabilities, enabling it to open specific web pages, inject arbitrary JavaScript code, modify proxy settings, and capture page content. The extension communicates with its C2 server via unencrypted HTTP at regular intervals, allowing operators to issue commands and retrieve exfiltrated data. This behavior mirrors other <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/68d9f447-1e3c-422a-a11e-3c285a012ded/Malicious-Chrome-Extension-Can-Steal-Login-Sessions-and-Turn-PCs-Into-Remote-Backdoors.pdf?AWSAccessKeyId=ASIA2F3EMEYESZ7OEEVD&Signature=tkgYwOGiwt1YBfviZUFPQx7Mq6c%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEHAaCXVzLWVhc3QtMSJIMEYCIQC7wjpkWckjd4x%2BB7Cb8Dtb93pL11OXpYDdVeMCiy0jHgIhAJMLPC1gQ70uIYax2QjS4Gq7meLYcMtnlVTB%2BCnqoLHqKvMECDkQARoMNjk5NzUzMzA5NzA1Igy5RfLFPvyEQCtoKEEq0AQYQk16rfd0oYBICNKbpGyGVRD2PyF5pJaLBO79jNt7nrELXoP8yLDiLflAJd4o1HDao7rK0094xhvUiMSkmrB9PmnbXxDKakm2Q3OcdST8Az9MhP7zL%2B5XryY688Lvct72YEupk4NtvOntz4jrE6V2iDiLg%2BJ%2FA1NNXCzx6J1v43So99qu%2BKoztUz4yuPiRbDnnzGXQxkbkPQNVFkOF9wg40yU0bxdToKWNyg7

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarePatchphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Best Business Antivirus and Endpoint Protection Software for 2024

Next Post

N-able Patches Critical RCE Vulnerability in N-central Platform

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best Antivirus Software for Mac in 2026
September 7, 2026
Top 10 Best Endpoint Detection & Response (EDR) Solutions in 2026
September 7, 2026
Critical Software Vulnerabilities Surge 500% Monthly
September 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us