PEEP is a RedExt-derived Chromium browser-extension remote-access and post-exploitation toolkit that masquerades as a “Smart Bookmarks” extension. It is deployed after an attacker has already obtained code execution or administrative access, and can be silently installed into Google Chrome or Microsoft Edge profiles on Windows systems. PEEP collects browsing history, active-tab metadata, session cookies, form and clipboard data, screenshots, page content, and browser storage. Theft of active session cookies enables reuse of authenticated sessions until they are revoked, potentially bypassing password and MFA challenges.
The extension polls command-and-control infrastructure over plaintext HTTP and can execute browser-side actions including page navigation, JavaScript injection, page capture, and proxy-configuration changes. A native-messaging companion bridges the browser sandbox to the Windows host, enabling shell-command execution, file operations, and process and service discovery in the current user’s security context. PEEP maintains browser persistence through manipulated Chromium extension-integrity preferences, enterprise extension-install policies, sideloading, and a service-worker cache fallback that can retain malicious functionality while leaving benign-looking extension source files. No confirmed victims, target sectors, threat-actor attribution, or initial-access mechanism has been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The browser extension can call a companion Windows program, enabling shell commands...
install_silent.ps1 and patch_secure_prefs.ps1 alter Secure Preferences and install the extension; force_enable.ps1 re-registers it through registry and external-extension mechanisms.
NM_SHELL runs a command through cmd, PowerShell, Bash, or sh via nm_host.exe.
PEEP also accepts commands to open pages, inject JavaScript, change proxy settings, and capture page content.
The browser extension can call a companion Windows program, enabling... discovery of running processes and services.
The browser extension can call a companion Windows program, enabling... discovery of running processes and services.
The native host supports list_dir, search_files, stat_path, and NM_LIST_DIR/NM_SEARCH commands.
DOMSNAPSHOT, LOCALSTORAGEDUMP, SESSIONSTORAGEDUMP, DOWNLOADS, BOOKMARKS, and native-host read-file commands collect browser and local-host data.
PEEP also accepts commands to open pages, inject JavaScript, change proxy settings, and capture page content.
It gathers... screenshots... PEEP also accepts commands to... capture page content.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Chromium-based post-compromise toolkit installed after attackers obtain code execution or administrative access. It steals browser data—including session cookies, form data, clipboard contents, screenshots, and storage data—and polls an HTTP C2 server. Its native-messaging host bridges the browser to Windows, enabling shell execution, file operations, and process/service discovery. It persists through Secure Preferences forgery, enterprise force-install policies, sideloading, and ScriptCache fallback.
A Chromium-based post-compromise toolkit that is silently installed into Chrome or Edge profiles after attackers already have code execution or administrative access. It steals cookies, browser and session data, form data, clipboard contents, screenshots, and storage data; receives C2 commands; and uses a Windows native-messaging host to execute shell commands, perform file operations, and enumerate processes and services. It persists through forged Chrome Secure Preferences values, enterprise force-install policies, sideloading, and a ScriptCache fallback.
PEEP is a RedExt-derived Chromium browser-extension RAT that establishes persistence in Chrome or Edge, polls a plaintext-HTTP C2 approximately every 30 seconds, and steals cookies, browsing history, open-tab data, credentials captured from web forms, screenshots, DOM and web-storage data, clipboard content, downloads, and bookmarks. It bypasses extension integrity protections through Secure Preferences HMAC forgery, enterprise force-install policies, sideloading, and a ScriptCache fallback. Through the com.peep.lab native-messaging host (nm_host.exe), it crosses the browser sandbox to execute shell commands and perform filesystem, process, and service operations in the logged-in user's context.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.