CuraSec

Plan active

PEEP Toolkit Uses Chrome/Edge Extensions as Post-Compromise Backdoor

2026-09-08 15:04 UTC · The Hacker News · read the source ↗ #post-exploitation#browser-security#persistence
  • Engineer — Learn: Novel post-compromise persistence technique that abuses Chromium’s Secure Preferences to silently inject malicious extensions — no active exploitation signals, but informs browser hardening strategy: audit enterprise extension allowlists and monitor Secure Preferences file integrity.
  • SOC/IR — Plan: New persistence TTP worth adding detection coverage for this quarter: build hunts for unexpected modifications to Chrome/Edge Secure Preferences files and unauthorized extension injection outside the Web Store on managed endpoints, mapping to ATT&CK T1176.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.