New Chrome Extension Steals Login Sessions, Creates Backdoors
Key Takeaways A new malicious Chrome extension, dubbed PEEP, can steal active login sessions and establish persistent backdoors on compromised Windows systems. PEEP masquerades as “Smart...
Key Takeaways
- A new malicious Chrome extension, dubbed PEEP, can steal active login sessions and establish persistent backdoors on compromised Windows systems.
- PEEP masquerades as “Smart Bookmarks” and leverages an existing compromise to install silently on Chrome and Edge browsers.
- The extension grants attackers extensive access to browser data, including cookies, history, and form data, and can execute commands on the host system via a native messaging bridge.
- Its sophisticated persistence mechanisms make removal challenging, requiring more than just uninstalling the extension.
- The threat highlights the severe risks posed by malicious browser add-ons, particularly those that gain operating system-level control.
A sophisticated malicious Chrome extension, identified as PEEP, has been uncovered, capable of exfiltrating active user login sessions and transforming an already compromised Windows machine into a remote backdoor. This discovery underscores the evolving danger posed by browser add-ons when they achieve elevated access to the underlying operating system.
The PEEP toolkit does not act as an initial access vector. Instead, it relies on adversaries having prior code execution capabilities or administrative privileges on a target system. Once these prerequisites are met, attackers can surreptitiously inject the extension into Chrome or Edge browser profiles. Its installation mechanisms are designed to bypass standard browser security checks, approval prompts, and visible warnings, ensuring a silent deployment. For a detailed analysis, refer to the SOCRadar report.
Security researchers at SOCRadar identified this operation, naming the toolkit PEEP. It is a Chromium-based post-compromise tool derived from the open-source RedExt project. SOCRadar said in a report that their investigation revealed a primary build of PEEP, disguised as “Smart Bookmarks” version 1.3.0, alongside a testing variant and an exposed development repository.
While the full extent of PEEP’s victim count remains undetermined, a snapshot from a command-and-control (C2) server indicated 34 agent entries, 10 active sessions, and 507 data records. However, these figures include test identifiers, preventing a precise count of actual compromised devices. Regardless, the design of PEEP poses a significant threat, as stolen session cookies can grant attackers unauthorized access to user accounts without requiring passwords or multi-factor authentication, until the sessions are explicitly revoked. This deep dive into PEEP’s capabilities is available in the SOCRadar’s full report.
Malicious Chrome Extension Capabilities
Upon activation, PEEP demands extensive permissions within the browser, requesting access to user tabs, cookies, browsing history, bookmarks, downloads, browser settings, scripting capabilities, and all websites. This broad access allows it to meticulously collect sensitive data including browsing history, details of open tabs, session cookies, form submissions, clipboard contents, screenshots, and both local and session storage data. This comprehensive data collection provides attackers with an in-depth view of a victim’s online activities, as detailed in the SOCRadar’s full report.
The ability to steal session cookies is particularly alarming because a valid cookie inherently verifies a user’s prior authentication. As documented in various security analyses, an attacker possessing such a token can hijack an active session, effectively bypassing subsequent password or multi-factor authentication requirements until the session is invalidated. PEEP also features command-and-control (C2) capabilities, enabling it to open specific web pages, inject arbitrary JavaScript code, modify proxy settings, and capture page content. The extension communicates with its C2 server via unencrypted HTTP at regular intervals, allowing operators to issue commands and retrieve exfiltrated data. This behavior mirrors other <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/68d9f447-1e3c-422a-a11e-3c285a012ded/Malicious-Chrome-Extension-Can-Steal-Login-Sessions-and-Turn-PCs-Into-Remote-Backdoors.pdf?AWSAccessKeyId=ASIA2F3EMEYESZ7OEEVD&Signature=tkgYwOGiwt1YBfviZUFPQx7Mq6c%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEHAaCXVzLWVhc3QtMSJIMEYCIQC7wjpkWckjd4x%2BB7Cb8Dtb93pL11OXpYDdVeMCiy0jHgIhAJMLPC1gQ70uIYax2QjS4Gq7meLYcMtnlVTB%2BCnqoLHqKvMECDkQARoMNjk5NzUzMzA5NzA1Igy5RfLFPvyEQCtoKEEq0AQYQk16rfd0oYBICNKbpGyGVRD2PyF5pJaLBO79jNt7nrELXoP8yLDiLflAJd4o1HDao7rK0094xhvUiMSkmrB9PmnbXxDKakm2Q3OcdST8Az9MhP7zL%2B5XryY688Lvct72YEupk4NtvOntz4jrE6V2iDiLg%2BJ%2FA1NNXCzx6J1v43So99qu%2BKoztUz4yuPiRbDnnzGXQxkbkPQNVFkOF9wg40yU0bxdToKWNyg7
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.