hacker-news · Crawled Sep 8, 2026
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
9 IoCs 1 Malware
Read original article ↗
AI Summary
PEEP is a post-compromise Chromium-based toolkit that installs a malicious browser extension to establish persistence and enable command-and-control (C2) operations within compromised Chrome or Edge browsers. The malware bypasses browser security checks by manipulating Secure Preferences and uses native messaging to execute host-level commands, steal credentials, and exfiltrate browsing data. It communicates with C2 servers every 30 seconds over HTTP, supports remote updates, and includes PowerShell and Python scripts for cross-platform deployment, indicating active targeting of both Windows and Linux environments.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 9 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 206[.]237[.]30[.]232 | Details → |
| Domain | xfjcc[.]fun | Details → |
| Filename | nm_host.exe | Details → |
| Filename | install_silent.ps1 | Details → |
| Filename | patch_secure_prefs.ps1 | Details → |
| Filename | force_enable.ps1 | Details → |
| Filename | patch_secure_prefs_linux.py | Details → |
| Filename | content.js | Details → |
| SHA-256 | ejkndncpkdcjcikfhiamcdehdoegilbj | Details → |
MITRE ATT&CK TTPs 23 techniques
T1003 OS Credential Dumping · Credential Access T1013 T1013 T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1078.001 Default Accounts · Defense Evasion T1078.002 Domain Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1086 T1086 T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1136.001 Local Account · Persistence T1190 Exploit Public-Facing Application · Initial Access T1218.011 Rundll32 · Defense Evasion T1548.001 Setuid and Setgid · Privilege Escalation T1548.002 Bypass User Account Control · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access