🔍 Contexte
Publié le 4 septembre 2026 par la SOCRadar Threat Research Unit (STRU), cet article présente une analyse technique approfondie de PEEP, un toolkit de post-exploitation basé sur les navigateurs Chromium, découvert et analysé via la plateforme Extended Threat Intelligence (XTI) de SOCRadar.
🧩 Description de la menace
PEEP est un Remote Access Tool (RAT) déguisé en extension Chrome nommée “Smart Bookmarks” (version 1.3.0). Il s’agit d’un dérivé opérationnel du framework open-source RedExt, enrichi de capacités supplémentaires :
- Pont de messagerie native via
com.peep.lab/nm_host.exe(Node.js v18.5.0) - Panneau C2 Flask/SQLite (Python 3.12, Werkzeug 3.1.8)
- Scripts d’installation PowerShell silencieux avec falsification des HMAC-SHA256 de Chromium
- Persistance multi-couches : forge des Secure Preferences, force-install enterprise, sideloading, fallback ScriptCache (“Ghost Anchor”)
⚙️ Architecture et fonctionnement
L’agent (background.js, Manifest V3) balise le serveur C2 toutes les 30 secondes en HTTP non chiffré vers l’IP 206.237.30.232 (AS55933, Cloudie Limited, Hong Kong). Il exfiltre automatiquement cookies, historique de navigation et métadonnées des onglets.
Le pont natif nm_host.exe étend les capacités au niveau OS :
- Exécution de commandes shell (cmd, PowerShell, bash)
- Gestion du système de fichiers
- Énumération des processus et services
Le C2 expose deux ports : tcp/5001 (panneau de contrôle + API agent) et tcp/5002 (répertoire de staging ouvert contenant sources, builds, clés de signature).
🗂️ Indicateurs opérationnels
- 37 commandes primaires documentées dans agent_config.json
- 38 variantes ZIP de builds (peep-v9 à peep-v29)
- Clé privée de signature incluse dans tous les packages
- Panneau C2 en chinois traditionnel (“登入 – AI · 法客-P”)
- Journal de QA
CHROME150-LIVE-RESULT.mdrédigé entièrement en chinois traditionnel - Mention “authorized CTF environment only” utilisée comme prétexte de légitimité
👤 Profil de l’opérateur
Acteur non identifié, probablement sinophone (artefacts en chinois traditionnel, confiance modérée). Capacité technique élevée mais tradecraft opérationnel faible (C2 non chiffré, clés exposées, intervalles de beacon statiques). Développement assisté par IA confirmé par la présence d’un panneau C2 brandé “AI”.
📊 Type d’article
Analyse technique détaillée produite par une équipe de threat intelligence, visant à documenter les capacités, l’infrastructure et les IOCs d’un nouveau toolkit de post-exploitation pour permettre la détection et le blocage.
🧠 TTPs et IOCs détectés
TTP
- T1583 — Acquire Infrastructure (Resource Development)
- T1587.001 — Develop Capabilities: Malware (Resource Development)
- T1176 — Browser Extensions (Persistence)
- T1059.001 — Command and Scripting Interpreter: PowerShell (Execution)
- T1059.003 — Command and Scripting Interpreter: Windows Command Shell (Execution)
- T1059.007 — Command and Scripting Interpreter: JavaScript (Execution)
- T1553 — Subvert Trust Controls (Defense Evasion)
- T1112 — Modify Registry (Defense Evasion)
- T1036 — Masquerading (Defense Evasion)
- T1027 — Obfuscated Files or Information (Defense Evasion)
- T1539 — Steal Web Session Cookie (Credential Access)
- T1056.003 — Input Capture: Web Portal Capture (Credential Access)
- T1115 — Clipboard Data (Credential Access)
- T1057 — Process Discovery (Discovery)
- T1007 — System Service Discovery (Discovery)
- T1083 — File and Directory Discovery (Discovery)
- T1518 — Software Discovery (Discovery)
- T1217 — Browser Information Discovery (Discovery)
- T1113 — Screen Capture (Collection)
- T1005 — Data from Local System (Collection)
- T1119 — Automated Collection (Collection)
- T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
- T1571 — Non-Standard Port (Command and Control)
- T1105 — Ingress Tool Transfer (Command and Control)
- T1090 — Proxy (Command and Control)
- T1041 — Exfiltration Over C2 Channel (Exfiltration)
IOC
- IPv4 :
206.237.30.232— AbuseIPDB · VT · ThreatFox - Domaines :
xfjcc.fun— VT · URLhaus · ThreatFox - Domaines :
new.xfjcc.fun— VT · URLhaus · ThreatFox - Domaines :
newadmin.xfjcc.fun— VT · URLhaus · ThreatFox - Domaines :
newapi.xfjcc.fun— VT · URLhaus · ThreatFox - URLs :
http://206.237.30.232:5001/api/register— URLhaus - URLs :
http://206.237.30.232:5001/api/commands— URLhaus - URLs :
http://206.237.30.232:5001/api/exfil— URLhaus - URLs :
http://206.237.30.232:5001/api/extension_update/— URLhaus - URLs :
http://206.237.30.232:5001/api/extension_crx/— URLhaus - URLs :
http://206.237.30.232:5001/health— URLhaus - URLs :
http://206.237.30.232:5001/login— URLhaus - SHA256 :
86a5fb2f14d175d1c13a7b49b55b968b2a5e96afc944d85a31b3db906af00beb— VT · MalwareBazaar - SHA256 :
6700e30a3224248085d30f2eb727cea28dec288355fca6753449a26d1c1d1eee— VT · MalwareBazaar - SHA256 :
9402c0198ae5c8bed14cdeaabe7e8b25625debbc62a900cfcdb82d34a35ab528— VT · MalwareBazaar - SHA256 :
8edd653910f3217c96a603e8ce9e5e409d3b8674476f22e0a3afe870bf3870b1— VT · MalwareBazaar - SHA256 :
87db7138a80117ddf2989827c1dde09ee73c7a252d511c74ed66af2fe34e2987— VT · MalwareBazaar - SHA256 :
259d8eddb6caf509d7bffa2b4c0dd7d89668800c870f529729ac2efdc1853fb6— VT · MalwareBazaar - SHA256 :
e46aee4ca43ba66666f6572c62365cf57642f2cf1f6eca00fcf8eb33a291d66d— VT · MalwareBazaar - SHA256 :
f031c00f592aa5e98893b4532f743362fed7fb0a485e8a3c0ad4de677f1d7415— VT · MalwareBazaar - SHA256 :
a43bf7f81507c8f9d0942fed331e7590a43044a6d219ec1005974bf1a81974a1— VT · MalwareBazaar - SHA256 :
b4e3ca8f44477b9ade1272f92516202f83a80219c8bd6176527a6d624214e893— VT · MalwareBazaar - SHA256 :
8e988b915b75dd749e3f4e1ca7ee21746885b4fe34e8a246e6f10f5d892a675f— VT · MalwareBazaar - SHA256 :
9c6b269e5087a40b4552f72e9ff13d9b39e433af5075ad68f57e9b5240a590d8— VT · MalwareBazaar - SHA256 :
207e0d47c4e5493ef7313eb1faeb1c6195923c89f263e548609a6838dd91ec0c— VT · MalwareBazaar - Fichiers :
nm_host.exe - Fichiers :
install_silent.ps1 - Fichiers :
patch_secure_prefs.ps1 - Fichiers :
force_enable.ps1 - Fichiers :
background.js - Fichiers :
content.js - Fichiers :
manifest.json - Fichiers :
agent_config.json - Fichiers :
update.xml - Fichiers :
nm_host.js - Fichiers :
peep.crx - Fichiers :
peepe.crx - Fichiers :
CHROME150-LIVE-RESULT.md - Fichiers :
peep_agent_meta.json - Fichiers :
extension.pem - Fichiers :
patch_secure_prefs_linux.py - Fichiers :
install_nm_host.sh - Chemins :
%LOCALAPPDATA%\PEEP\crx - Chemins :
%LOCALAPPDATA%\PEEP\nm_host\com.peep.lab - Chemins :
%LOCALAPPDATA%\PEEP\extensions\<id> - Chemins :
~/.peep_nm_host.log - Chemins :
~/.config/google-chrome
⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 10 septembre 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- PEEP (rat)
- RedExt (framework)
- nm_host.exe (tool)
- install_silent.ps1 (tool)
- patch_secure_prefs.ps1 (tool)
- force_enable.ps1 (tool)
🟢 Indice de vérification factuelle : 70/100 (haute)
- ⬜ socradar.io — source non référencée (0pts)
- ✅ 43030 chars — texte complet (fulltext extrait) (15pts)
- ✅ 47 IOCs dont des hashes (15pts)
- ✅ 7/10 IOCs confirmés (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
- ✅ 26 TTPs MITRE identifiées (15pts)
- ✅ date extraite du HTML source (10pts)
- ⬜ aucun acteur de menace nommé (0pts)
- ⬜ pas de CVE à vérifier (0pts)
IOCs confirmés externellement :
206.237.30.232(ip) → VT (7/89 détections)86a5fb2f14d175d1…(sha256) → VT (14/76 détections)6700e30a32242480…(sha256) → VT (22/76 détections)9402c0198ae5c8be…(sha256) → VT (18/76 détections)xfjcc.fun(domain) → VT (6/89 détections)
🔗 Source originale : https://socradar.io/blog/peep-browser-rat-chrome-extension/