Fetch was blocked, so I’ll work from search results and the story briefs already in the brief.TITLE: One Forged File. Months of Browser Access.
The attacker already had admin rights. Then they forged Chromium’s Secure Preferences, dropped a fake bookmarks extension into Chrome and Edge, and kept executing host commands after you thought the box was clean. That’s the bill for PEEP: weeks of browser-profile forensics, mass token revocation, and a cybersecurity closure that fails because the backdoor sits in the one app your users never stop using.
Researchers laid out the toolkit this week. It pretends to be a bookmarks helper. Nobody gets a Web Store prompt. Nobody clicks Allow. Once an operator already has administrative or code-execution access, the installer writes the extension straight into Chrome and Edge profiles and forges the browser’s own trust file so Chromium treats it as legitimate.
Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences.
Read that again. PEEP is the stay-behind kit. The point is command execution on the host through a process your EDR already trusts, your users already run all day, and your playbooks barely inspect.

Forged Preferences Survive the Reimage You Already Did
Plenty of incident response checklists still end on services, scheduled tasks, Run keys, and a known-bad hash. PEEP does not live there. Chromium’s Secure Preferences file is supposed to prove the browser’s settings were not tampered with. Forge it, and the browser becomes the liar in the room. The malicious extension looks like it always belonged.
Roaming profiles and non-persistent VDI make the cleanup expensive. Wipe the disk and the poisoned profile can sync back with the user. Recycle a pool and the extension arrives as the user’s bookmarks. You will spend months chasing hosts that look clean in threat detection because the persistence is a preference file, not a service.
Stop treating browsers as a content-filter problem. Your firewall will not see a post-compromise channel riding inside an already-authenticated Chrome process talking to a site the user is allowed to visit. Edge telemetry that only screams about brute-force logons at the perimeter will stay quiet while a fake bookmarks add-on shells the host.
When that extension can run host commands, it can also read the cookie jar in the same profile. SSO cookies, saved cloud tokens, intranet logins: they travel with the profile you failed to treat as hostile. A “bookmarks” add-on becomes a session harvester without a second implant.
The same week offered the no-implant version of this story. Operators posing as IT called directors and VPs, walked them through adversary-in-the-middle sign-ins, and stole Microsoft 365 tokens. Residential proxies made those sign-ins look like they came from home. Then the crew stole data and started extortion. Different door. Same object of desire: a live session in software you already permit.

Berlin just had another government credential dump land online. Germany’s information security agency also warned about the Rhysida group. Public password lists are the messy, noisy cousin of PEEP. One is a paste site. The other is a forged preference. Both leave you rotating logins and hoping sessions actually died.
Skip Browser Profiles and Your IR Lies to You
Confirmed admin-level access on a workstation means Chrome and Edge profiles are evidence, not scenery. You need actions you can run this afternoon, then controls that stay on.
- Dump the extension inventory from every Chrome and Edge profile on the host, including extra profiles people create to keep work and home separate.
- Diff extension IDs and install paths against your enterprise allowlist and the official store. A bookmarks helper that never came from the store is the lead.
- Capture hashes and timestamps for Secure Preferences and Preferences. Writes clustered around the intrusion window are the implant.
- Revoke refresh tokens, force sign-out, and rotate cloud credentials for every account that touched a suspect profile. A password change that leaves tokens alive is a gift.
- Enforce extension allowlists by policy. Kill unpacked, developer-mode, and force-installed add-ons you did not deploy.
- Alert when Secure Preferences change, when a new extension directory appears, or when Chrome or Edge spawns cmd, PowerShell, or other unexpected children.
- Put executive IT callbacks on a published number. A voice request to approve a login is identity incident response, not a help-desk ticket.
- Add browser-profile inspection to every containment checklist that currently stops at malware removed. Fold this into security hardening the same way you already treat startup persistence.
You do not need a new console for this. You need cyber security operations that admit the browser is a privileged runtime. Isolate the machine and leave the user’s cloud sessions intact, and they keep working from a phone. Host-only containment is incomplete containment.
Stolen Sessions Make Cybersecurity Closure a Guess
Patch the host. Reset local admin. Watch EDR go quiet. You can still lose. If PEEP’s extension remains in a profile, threat-protection dashboards stay green while host commands keep landing. If an executive approved a fake IT prompt, the token outlives the password reset. If a Berlin-style dump includes your SaaS logins, every closed ticket is incomplete until those sessions are dead.

The operational failure is declaring victory when process telemetry calms down. Calm is the design goal of a forged preference file. Defense in depth that never inspects the browser’s trust files is a poster on the wall.
Hunt those files. Treat extension allowlists as production policy. Put token revocation in the same hour as the host isolation. Until you do, you are cleaning the wrong layer, and the access you thought you killed will still be sitting in Chrome tomorrow morning.
Sources
- PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
- Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
- Berlin investigates new data leak after hackers publish stolen login credentials
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
