hacker-news · Crawled Sep 8, 2026

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

9 IoCs 1 Malware
Read original article ↗

AI Summary

PEEP is a post-compromise Chromium-based toolkit that installs a malicious browser extension to establish persistence and enable command-and-control (C2) operations within compromised Chrome or Edge browsers. The malware bypasses browser security checks by manipulating Secure Preferences and uses native messaging to execute host-level commands, steal credentials, and exfiltrate browsing data. It communicates with C2 servers every 30 seconds over HTTP, supports remote updates, and includes PowerShell and Python scripts for cross-platform deployment, indicating active targeting of both Windows and Linux environments.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 9 extracted

Type Value Detail
IP 206[.]237[.]30[.]232 Details →
Domain xfjcc[.]fun Details →
Filename nm_host.exe Details →
Filename install_silent.ps1 Details →
Filename patch_secure_prefs.ps1 Details →
Filename force_enable.ps1 Details →
Filename patch_secure_prefs_linux.py Details →
Filename content.js Details →
SHA-256 ejkndncpkdcjcikfhiamcdehdoegilbj Details →

MITRE ATT&CK TTPs 23 techniques