PEEP malware backdoor found in Chrome and Edge

Cybersecurity researchers disclosed PEEP on September 7, 2026, a sophisticated post-exploitation toolkit that poses as a browser-bookmarks extension and can turn Chrome and Edge profiles into persistent host command-execution backdoors. The malware requires prior administrative access but enables attackers to maintain control after initial compromise.

7 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

PEEP turns Chrome and Edge into malware backdoors

kite:cybersecurityother22d ago kagi ↗

Cybersecurity researchers disclosed PEEP, a Chromium-based post-exploitation toolkit that masquerades as a browser-bookmarks extension and can turn Chrome and Edge profiles into backdoors after an attacker has already gained administrative or code-execution access on a host [thehackernews.com#1]. SOCRadar said PEEP's installer injects the extension directly into Chrome or Edge profiles and bypasse

🔹 The Hacker News PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation t

mastodon:infosec-exchangeother22d ago kagi ↗

🔹 The Hacker News PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edg

‼️ PEEP turns Chrome and Edge into host-level backdoors after compromise. With prior admin or code-execution access, the Smart Bookmarks extension steals session cookies and credentials, then uses Chr

mastodon:infosec-exchangeother22d ago kagi ↗

‼️ PEEP turns Chrome and Edge into host-level backdoors after compromise. With prior admin or code-execution access, the Smart Bookmarks extension steals session cookies and credentials, then uses Chromium native messaging to run host commands. Read: https:// thehackernews.com/2026/09/peep -turns-chrome-and-edge-into-post.html

Researchers detailed PEEP, a Chromium post-exploitation framework posing as a bookmarks extension for Chrome and Edge. It requires prior admin access but then provides persistent host command executio

mastodon:infosec-exchangeother20d ago kagi ↗

Researchers detailed PEEP, a Chromium post-exploitation framework posing as a bookmarks extension for Chrome and Edge. It requires prior admin access but then provides persistent host command execution from inside the browser. This matters because trusted browser processes can blind EDR and extend dwell time. # PeepMalware # BrowserSecurity # PostExploitation https:// cyberworldops.eu/en/peep-turn