Researchers identified PEEP, a Chromium browser-extension remote-access and post-exploitation toolkit derived from RedExt that masquerades as a Smart Bookmarks extension. Once an operator has obtained prior code execution or administrative access, PEEP can persist in Chrome or Edge through extension sideloading, enterprise policies, forged Secure Preferences integrity values, or a ScriptCache fallback; it collects browser telemetry and cookies, polls command-and-control (C2) over plaintext HTTP, and uses a native-messaging host to execute commands and manipulate files as the logged-in user.
The reported staging and C2 infrastructure was hosted at 206.237.30.232 on ports 5001 and 5002, reflecting adversary acquisition and use of external infrastructure. An exposed repository reportedly contained source code, iterative builds, logs, and the extension's primary private signing key. Traditional Chinese-language development artifacts indicate a likely Chinese-speaking operator, but no victims, campaign targets, confirmed criminal use, or nation-state attribution have been established.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers assessed the unidentified PEEP operator as probably Sinophone with moderate confidence, citing Traditional Chinese text in the C2 panel and QA artifacts. The report also characterized the operator's operational security as weak because of exposed signing keys, static beaconing, and unencrypted C2 traffic.
SOCRadar detailed that the RedExt-derived PEEP “Smart Bookmarks” extension can steal browser sessions and data and use a native-messaging host to execute shell commands and conduct file and process operations on compromised Windows hosts. The report identified persistence methods, including forged Secure Preferences values, force-install policies, sideloading, and ScriptCache fallback, along with extension IDs, domains, host artifacts, and API endpoints; the reported server counts did not confirm victim numbers.
Researchers documented PEEP, a RedExt-derived Chromium browser-extension remote-access toolkit masquerading as “Smart Bookmarks,” operating from 206.237.30.232. The exposed infrastructure reportedly included a C2/API service, staging repository, iterative builds, source code, logs, and the private signing key for the primary extension identity; no victims or confirmed deployments were identified.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecyberveille.ch
Open sourcecysecurity.news
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcesocradar.io
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.