Bookmarks add-on hides a backdoor that crosses the browser sandbox

SOCRadar details PEEP, a post-compromise toolkit that rides a fake bookmarks extension from the browser out to host-level command execution.

CSBadmin
2 Min Read

Malware that lives inside a signed browser process can dodge the scrutiny aimed at fresh binaries, and SOCRadar says PEEP does exactly that. The toolkit, built for attackers who already hold administrative or code-execution access, hides as a bookmarks extension inside Chrome and Edge.

Delivery bypasses the Web Store entirely: an installer drops the add-on straight into browser profiles and patches Chromium’s Secure Preferences file so the browser trusts and auto-enables it without asking the user. A native-messaging companion then stretches the implant beyond telemetry into full host command execution and file management.

Once running, the extension, disguised as “Smart Bookmarks,” polls its command-and-control server every 30 seconds over plaintext HTTP, harvesting browsing history, active-tab metadata, and session cookies. When a task needs OS access, it invokes an auxiliary executable through the Native Messaging Host bridge, letting operators run shell commands, manage files, and enumerate processes and services. The toolkit descends from RedExt, an open-source browser red-teaming framework tied to earlier GlassWorm attacks, and adds installation routines, an update channel, and a broader command set.

Persistence comes from sideloading, enterprise force-install policies, and preference-integrity manipulation, with PowerShell scripts and a Python counterpart suggesting the operators are also building for Linux. The activity is unattributed, though Chinese-language artifacts in the source point to a Chinese-speaking actor. Because its logic runs inside a signed browser process, PEEP slips past detection that keys on unsigned binaries.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.