Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: post-exploitation (2 articles)Clear

PEEP toolkit hijacks Chrome and Edge into backdoors that run host commands

Researchers disclosed a post-exploitation toolkit called PEEP that turns Chrome and Edge into backdoors for stealing credentials and running commands on the host. After an attacker already has administrative or code-execution access, PEEP's installer injects a malicious extension disguised as a bookmarks tool directly into browser profiles, forging Chromium's own integrity settings to bypass the Web Store and skip user approval prompts. The planted extension then serves as a covert channel to harvest credentials and execute operating-system commands. Because it abuses a trusted, ever-present browser and hides its extension from the usual checks, it can persist quietly on a compromised machine, a reminder that browsers themselves are a rich post-compromise attack surface.

Check
Hunt for tampering with Chromium's secure preferences file and for extensions loaded outside the Web Store, and treat an unexpected browser extension on a server or admin workstation as a possible backdoor.
Affected
Windows systems an attacker already compromised with admin or code-execution access; PEEP silently installs a browser extension by forging integrity settings, then uses it to steal credentials and run host commands.
Fix
Enforce enterprise extension allowlisting through browser policy, monitor for secure-preferences tampering and unapproved extensions, restrict local administrator rights that enable the install, and include browser artifacts in endpoint detection and incident response.

New Linux backdoor 'PamDOORa' silently steals SSH credentials from every user logging into a compromised server - and erases its tracks from the logs

Group-IB and Flare disclosed PamDOORa, a new Linux backdoor for sale on the Russian-speaking Rehub cybercrime forum at $900 (down from $1,600). PamDOORa hijacks the Linux Pluggable Authentication Module (PAM) framework that handles SSH logins - so it intercepts every legitimate user's password as they authenticate, before any application-level logging fires. The backdoor injects a malicious pam_linux.so module into the authentication stack rather than replacing files. It also tampers with lastlog, btmp, utmp, and wtmp to erase attacker login traces - meaning incident response teams who SSH in to investigate will have their own credentials silently stolen. Group-IB notes the abuse method is not yet in MITRE ATT&CK.

Check
Audit /etc/pam.d/ for unfamiliar pam_*.so modules, particularly pam_linux.so. Compare loaded PAM modules against your distribution's default set. Hunt /tmp for files with random names containing XOR-encrypted credential captures.
Affected
All x86_64 Linux servers running OpenSSH for remote access. PamDOORa is post-exploitation, so attackers must already have root - but once installed it captures every SSH credential and persists invisibly. Acute risk: any Linux server compromised at any point in the past, regardless of remediation - PamDOORa survives standard cleanup unless PAM-specific auditing was performed.
Fix
Enable SELinux or AppArmor in enforcing mode to constrain PAM module loading. Install Auditd with DISA-STIG rules to alert on /etc/pam.d/ changes. Deploy rkhunter or chkrootkit for routine PAM rootkit detection. Treat any compromised Linux server as having fully exposed credentials - rotate every SSH key, password, and token.