Researchers disclosed a post-exploitation toolkit called PEEP that turns Chrome and Edge into backdoors for stealing credentials and running commands on the host. After an attacker already has administrative or code-execution access, PEEP's installer injects a malicious extension disguised as a bookmarks tool directly into browser profiles, forging Chromium's own integrity settings to bypass the Web Store and skip user approval prompts. The planted extension then serves as a covert channel to harvest credentials and execute operating-system commands. Because it abuses a trusted, ever-present browser and hides its extension from the usual checks, it can persist quietly on a compromised machine, a reminder that browsers themselves are a rich post-compromise attack surface.
Group-IB and Flare disclosed PamDOORa, a new Linux backdoor for sale on the Russian-speaking Rehub cybercrime forum at $900 (down from $1,600). PamDOORa hijacks the Linux Pluggable Authentication Module (PAM) framework that handles SSH logins - so it intercepts every legitimate user's password as they authenticate, before any application-level logging fires. The backdoor injects a malicious pam_linux.so module into the authentication stack rather than replacing files. It also tampers with lastlog, btmp, utmp, and wtmp to erase attacker login traces - meaning incident response teams who SSH in to investigate will have their own credentials silently stolen. Group-IB notes the abuse method is not yet in MITRE ATT&CK.