SECURITY·중요도 8·2026. 09. 07.·The Hacker News

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

── KO ──────────────────

PEEP는 Chrome과 Edge를 위한 복잡한 포스트-악용 툴킷이다.

PEEP는 Chrome과 Edge를 대상으로 한 복잡한 포스트-악용 툴킷으로, 웹 브라우저의 북마크 확장으로 위장한다. 이 툴킷은 사전 관리 권한이나 코드 실행 접근이 필요하며, 사용자의 프롬프트 없이 Chromium의 보안 기본 설정을 조작하여 확장을 프로필에 직접 주입한다.


── EN ──────────────────

PEEP is a complex post-exploitation toolkit for Chrome and Edge.

PEEP is a sophisticated post-exploitation toolkit targeting Chrome and Edge, masquerading as a bookmarks extension. It requires prior administrative or code execution access, injecting the extension directly into browser profiles while bypassing Store checks and user prompts by forging Chromium's Secure Preferences.

원문 보기 →목록으로