PEEP hijacks Chrome and Edge via forged extension profiles
The installer slips a “Smart Bookmarks” extension (ID ejkndncpkdcjcikfhiamcdehdoegilbj) straight into Chrome and Edge profiles by corrupting Chromium’s Secure Preferences integrity values. No Web Store approval, no user prompt – just a silent takeover.
Why it matters
Once the extension is in place, the browser becomes a foothold for a full‑blown backdoor. The toolkit can run native commands on the host, pull files, and ship browsing data back to the attacker every half‑minute.
Technical walk‑through
The extension talks to two hard‑coded C2 servers (206.237.30.232 and xfjcc.fun) over clear‑text HTTP, polling every 30 seconds. It uses a native‑messaging host (nm_host.exe) to break out of the browser sandbox and execute host‑level PowerShell scripts.
- PowerShell helpers:
install_silent.ps1,patch_secure_prefs.ps1,force_enable.ps1– enable developer mode, patch Secure Preferences, force‑install the extension. - Linux counterpart:
patch_secure_prefs_linux.pyshows the same technique works on Chromium on Linux. - API endpoints used for registration, telemetry and exfiltration:
/api/register,/api/agents/<id>/heartbeat,/api/extension_update/,/api/extension_crx/,/api/agents/<id>/task_result,/api/exfil,/health,/login
The toolkit harvests browsing history, active‑tab metadata, session cookies, public IP, locale and timezone data, then ships it back via the /api/exfil endpoint.
Who’s at risk
Any workstation running Google Chrome or Microsoft Edge on Windows or Linux can be compromised if the attacker can write to the user’s profile directory. Enterprise environments that use force‑install policies are especially vulnerable because the same sideloading technique can be baked into group policy.
Defensive steps
- Audit the
Secure Preferencesfile for unexpected modifications or mismatched integrity hashes. - Search for the extension ID
ejkndncpkdcjcikfhiamcdehdoegilbjin all user profiles; remove any stray entries. - Block outbound HTTP to
206.237.30.232andxfjcc.funat the network perimeter. - Disable native‑messaging hosts that you do not explicitly need; monitor for newly registered
nm_host.exebinaries. - Review group‑policy and enterprise force‑install settings for unknown extensions.
- Run endpoint detection rules that flag PowerShell scripts named
install_silent.ps1,patch_secure_prefs.ps1orforce_enable.ps1executing in user contexts.
Detecting the toolkit early hinges on spotting the odd combination of a browser extension and a native‑messaging host that talks to known C2 IPs. Once you’ve cleared the extension and its host, rotate any potentially exposed credentials and session cookies.
