{"id":1467,"date":"2026-09-08T13:42:04","date_gmt":"2026-09-08T08:12:04","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1467"},"modified":"2026-09-09T14:35:30","modified_gmt":"2026-09-09T09:05:30","slug":"peep-malware-chrome-edge-backdoor","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/","title":{"rendered":"PEEP Malware Turns Chrome and Edge Into Post-Compromise Backdoors"},"content":{"rendered":"<p>A malicious browser extension does not always need to begin with a deceptive Web Store installation. PEEP malware demonstrates what attackers could do after they already control an endpoint.<\/p>\n<p>SOCRadar&#8217;s Threat Research Unit identified PEEP as a Chromium-based post-exploitation toolkit disguised as a \u201cSmart Bookmarks\u201d extension. The recovered toolkit requires prior administrative or code-execution access. Therefore, PEEP is not an initial-access exploit or browser vulnerability.<\/p>\n<p>Instead, its distinctive technique starts after endpoint compromise. PEEP manipulates Chromium&#8217;s Secure Preferences integrity values to help install and retain a sideloaded extension. It then connects the extension to a native messaging host for operating-system access. The recovered host-side binary, <code>nm_host.exe<\/code>, targets Windows.<\/p>\n<h2>PEEP Malware at a Glance<\/h2>\n<table style=\"font-weight: 400; width: 100.167%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"11\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Information<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Threat<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\">PEEP<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Type<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Chromium-based post-exploitation toolkit<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Disguise<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\">\u201cSmart Bookmarks\u201d extension<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Browsers<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Google Chrome and Microsoft Edge<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Recovered host platform<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Windows<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Initial access<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Prior administrative or code-execution access\u00a0required<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Host bridge<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\"><code>com.peep.lab<\/code>\u00a0\/ <code>nm_host.exe<\/code><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">C2 communication<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Plaintext HTTP<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Polling interval<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Nominally every 30 seconds<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 35.4167%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Confirmed victim deployment<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 114.423%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Not\u00a0established\u00a0by available research<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>SOCRadar also describes PEEP as derived from the open-source RedExt framework rather than an entirely independent codebase.<\/p>\n<h2>How PEEP Malware Manipulates Chromium Secure Preferences<\/h2>\n<p>PEEP&#8217;s defining behavior is how it turns an existing endpoint compromise into persistent browser-level access.<\/p>\n<p>Its installation routines can inject the extension into Chrome and Edge profiles. One installer, <code>install_silent.ps1<\/code>, works with <code>patch_secure_prefs.ps1<\/code> to manipulate Chromium&#8217;s Secure Preferences data. The toolkit recalculates integrity values associated with the modified preferences so the browser accepts the changes.<\/p>\n<p>PEEP uses layered persistence through validated Secure Preferences state, enterprise force-install policies, a registered native-messaging host and a Ghost Anchor ScriptCache fallback.<\/p>\n<p>That enterprise-policy abuse matters because force installation itself is legitimate Chromium functionality. Google&#8217;s documentation states that <a href=\"https:\/\/chromeenterprise.google\/policies\/extension-install-forcelist\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=peep_malware\" target=\"_blank\" rel=\"nofollow noreferrer noopener\"><code>ExtensionInstallForcelist<\/code><\/a> can silently install specified extensions and prevent users from disabling or removing them. PEEP demonstrates how legitimate browser administration mechanisms can become useful after an attacker already controls the endpoint.<\/p>\n<h2>How nm_host.exe Takes PEEP Beyond the Browser<\/h2>\n<p>PEEP does not stop at browser surveillance.<\/p>\n<p>The extension communicates with a native messaging host named <code>com.peep.lab<\/code>. Its recovered Windows implementation uses <code>nm_host.exe<\/code> to bridge browser activity with operating-system functionality.<\/p>\n<p>Native messaging is another legitimate browser capability. Chrome permits extensions to exchange messages with registered native applications. On Windows, defenders should also inspect the registry locations used to register PEEP&#8217;s native messaging host. These include <code>HKLM\\SOFTWARE\\Google\\Chrome\\NativeMessagingHosts\\com.peep.lab<\/code> and <code>HKCU\\Software\\Google\\Chrome\\NativeMessagingHosts\\com.peep.lab<\/code>, along with corresponding Edge and <code>WOW6432Node<\/code> locations. These artifacts can help SOC teams identify the browser-to-host bridge during endpoint investigations.<\/p>\n<p>PEEP abuses that browser-to-host bridge for capabilities including:<\/p>\n<ul>\n<li>executing commands through supported shells;<\/li>\n<li>enumerating processes and services;<\/li>\n<li>reading, writing, renaming and deleting files;<\/li>\n<li>searching directories;<\/li>\n<li>retrieving system information; and<\/li>\n<li>managing other host-side operations.<\/li>\n<\/ul>\n<p>This distinction is important. The browser extension acts as PEEP&#8217;s primary agent, while <code>nm_host.exe<\/code> provides host-level command and file operations in the user context.<\/p>\n<h2>What PEEP Malware Can Collect from Chrome and Edge<\/h2>\n<p>Once active, PEEP&#8217;s agent contacts its command-and-control infrastructure over plaintext HTTP. The recovered configuration uses a nominal 30-second cycle for command polling and automated collection.<\/p>\n<p>The toolkit supports collection of:<\/p>\n<ul>\n<li>session cookies;<\/li>\n<li>recent browsing history;<\/li>\n<li>open tabs and active URLs;<\/li>\n<li>bookmarks and downloads;<\/li>\n<li>page DOM and web storage;<\/li>\n<li>screenshots;<\/li>\n<li>clipboard content on demand;<\/li>\n<li>browser and extension metadata; and<\/li>\n<li>password-like fields submitted through web forms.<\/li>\n<\/ul>\n<p>However, one distinction matters for credential-theft claims. SOCRadar found that PEEP can capture password-like fields from web pages, but it does not directly read Chrome&#8217;s saved-password database.<\/p>\n<p>Collected telemetry can be sent through <code>\/api\/exfil<\/code>, while command results can return through <code>\/api\/agents\/&lt;id&gt;\/task_result<\/code>. PEEP&#8217;s use of plaintext HTTP also creates a network-level detection opportunity. Because the traffic is unencrypted, network security controls with HTTP payload-inspection capabilities can inspect its traffic without first decrypting TLS. Security teams can therefore monitor outbound HTTP for PEEP-related endpoints and suspicious data transfers associated with its command-and-control infrastructure.<\/p>\n<h2>Why Session Cookies Make PEEP an Identity Risk<\/h2>\n<p>PEEP&#8217;s browser access creates an identity-security concern because authenticated browser state can be valuable after endpoint compromise.<\/p>\n<p>Session cookies may represent existing authenticated sessions to SaaS applications and other web services. Therefore, stealing usable session material can create a path to session abuse without requiring the attacker to obtain the user&#8217;s password again.<\/p>\n<p>This does not mean PEEP has been shown bypassing MFA or compromising specific SaaS services. The available research establishes its cookie-collection capability, not those downstream outcomes.<\/p>\n<p>The distinction changes the defensive priority. Responders investigating suspected PEEP activity should consider both the compromised Windows endpoint and authenticated sessions exposed through its browsers.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/All-Images-6_11zon-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Ensure Software Supply Chain Security with Hexnode UEM<\/h4><p>Explore how endpoint controls, software validation and browser extension governance can help reduce software supply chain risks.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/ensure-software-supply-chain-security-with-hexnode-uem\/\" aria-label=\"Ensure Software Supply Chain Security with Hexnode UEM\"><\/a><\/div><\/div><\/div>\n<h2>How Hexnode Controls Map to PEEP&#8217;s Browser-to-Host Chain<\/h2>\n<p>PEEP crosses endpoint, browser and identity boundaries. That makes Hexnode UEM, XDR and IdP relevant at different stages of the defensive workflow.<\/p>\n<h3>Restrict Unapproved Chrome Extensions with Hexnode UEM<\/h3>\n<p>PEEP specifically relies on installing an unauthorized Chromium extension. Hexnode UEM documents <a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/help\/how-to-configure-browser-settings-on-windows-devices\/\">Browser Settings<\/a> for managed Windows devices that can configure, automatically install, allow or restrict Google Chrome extensions.<\/p>\n<p>Administrators can also disable external extensions that are not listed in the Chrome Web Store. An <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-allowlist\/\">allowlist<\/a> can restrict Chrome to approved extension IDs.<\/p>\n<p>This directly addresses part of PEEP&#8217;s browser <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-a-cybersecurity-attack-surface\/\">attack surface<\/a>. However, these controls should not be presented as proof that UEM alone blocks PEEP after an attacker already has administrative or code-execution access.<\/p>\n<p>PEEP also modifies Windows-side artifacts. Hexnode UEM supports custom PowerShell and Batch script execution on managed Windows endpoints. Administrators can therefore use validated scripts for organization-specific inspection or remediation workflows where appropriate.<\/p>\n<h3>Investigate Post-Compromise Activity with Hexnode XDR<\/h3>\n<p>PEEP&#8217;s native host introduces endpoint behaviors beyond the extension itself. These include process discovery, shell execution and file-system operations.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> provides threat hunting, endpoint investigation and response capabilities across supported Windows and macOS environments. Its documented response actions include device isolation, process termination and file quarantine.<\/p>\n<p>For this incident, the relevant scope is the recovered Windows implementation of PEEP. Security teams can use endpoint telemetry and threat-hunting workflows to investigate suspicious activity associated with a suspected compromise.<\/p>\n<p>Hexnode XDR should not be described as specifically detecting PEEP unless a documented PEEP detection exists.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Why-XDR-IS-stronger-thumbnail\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            See how combining endpoint management with XDR can strengthen threat investigation, response and endpoint resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h3>Restrict Sensitive Access from Non-Compliant Devices<\/h3>\n<p>PEEP also shows why authenticated identity alone does not establish endpoint trust.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/idp\/\">Hexnode IdP<\/a> supports Conditional Access based on user identity, device compliance and security context, allowing access rules to account for both identity and device posture.<\/p>\n<p>This control addresses potential downstream exposure from compromised endpoints. It does not invalidate stolen cookies automatically or establish that PEEP can bypass authentication controls.<\/p>\n<h2>What Security Teams Should Check for PEEP Malware<\/h2>\n<p>Organizations investigating possible PEEP exposure should prioritize the artifacts documented by SOCRadar:<\/p>\n<ol>\n<li>Look for the primary \u201cSmart Bookmarks\u201d extension ID <code>ejkndncpkdcjcikfhiamcdehdoegilbj<\/code>.<\/li>\n<li>Check Chrome and Edge <code>NativeMessagingHosts<\/code> registry locations for <code>com.peep.lab<\/code>, including applicable <code>HKCU<\/code>, <code>HKLM<\/code> and <code>WOW6432Node<\/code> paths.<\/li>\n<li>Investigate unexpected <code>nm_host.exe<\/code> execution.<\/li>\n<li>Review <code>%LOCALAPPDATA%\\PEEP<\/code> for associated <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-are-cybersecurity-artifacts\/\">artifacts<\/a>.<\/li>\n<li>Investigate unauthorized changes to Chrome or Edge Secure Preferences.<\/li>\n<li>Review Chrome and Edge enterprise extension policies for unauthorized entries. For Edge, inspect <code>SOFTWARE\\Policies\\Microsoft\\Edge\\ExtensionInstallAllowlist<\/code> and other configured extension-control policies.<\/li>\n<li>Look for connections to documented PEEP infrastructure.<\/li>\n<li>Revoke potentially exposed <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-authenticated-session\/\">authenticated sessions<\/a> where compromise is suspected.<\/li>\n<li>Restrict browser extensions to approved business requirements.<\/li>\n<\/ol>\n<p>These steps address the distinctive PEEP chain rather than treating the incident as generic extension malware.<\/p>\n<h3>PEEP Shows Why the Browser Is Part of Endpoint Security<\/h3>\n<p>PEEP malware starts from an important assumption: the attacker already has endpoint access.<\/p>\n<p>From there, it converts Chrome or Edge into a persistent collection and control layer. Secure Preferences manipulation helps retain the extension, while native messaging bridges browser access to Windows host functionality.<\/p>\n<p>That makes browser-extension governance, endpoint investigation and session security interconnected defensive problems. Enterprises should treat extensions as privileged software, investigate unexpected browser-to-native-host relationships, and review authenticated sessions whenever a browser endpoint is suspected of compromise.<\/p>\n<p>PEEP does not introduce a new Chrome or Edge zero-day. Instead, it demonstrates how deeply an attacker can exploit legitimate browser functionality after the endpoint security boundary has already failed.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Endpoint Security Beyond the Browser<\/h5><p>Bring endpoint management, threat investigation and access controls together with Hexnode. Start your 14-day free trial with no credit card required.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A malicious browser extension does not always need to begin with a deceptive Web Store&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1471,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16],"class_list":["post-1467","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PEEP Malware Turns Chrome and Edge Into Backdoors<\/title>\n<meta name=\"description\" content=\"PEEP malware turns compromised Chrome and Edge sessions into backdoors for data theft and host commands. Learn how enterprises can respond.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PEEP Malware Turns Chrome and Edge Into Backdoors\" \/>\n<meta property=\"og:description\" content=\"PEEP malware turns compromised Chrome and Edge sessions into backdoors for data theft and host commands. Learn how enterprises can respond.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-08T08:12:04+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-09T09:05:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"PEEP Malware Turns Chrome and Edge Into Post-Compromise Backdoors\",\"datePublished\":\"2026-09-08T08:12:04+00:00\",\"dateModified\":\"2026-09-09T09:05:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/\"},\"wordCount\":1309,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp\",\"articleSection\":[\"Malware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/\",\"name\":\"PEEP Malware Turns Chrome and Edge Into Backdoors\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp\",\"datePublished\":\"2026-09-08T08:12:04+00:00\",\"dateModified\":\"2026-09-09T09:05:30+00:00\",\"description\":\"PEEP malware turns compromised Chrome and Edge sessions into backdoors for data theft and host commands. Learn how enterprises can respond.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"PEEP Malware Turns Chrome and Edge Into Post-Compromise Backdoor\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/peep-malware-chrome-edge-backdoor\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PEEP Malware Turns Chrome and Edge Into Post-Compromise Backdoors\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PEEP Malware Turns Chrome and Edge Into Backdoors","description":"PEEP malware turns compromised Chrome and Edge sessions into backdoors for data theft and host commands. Learn how enterprises can respond.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/","og_locale":"en_US","og_type":"article","og_title":"PEEP Malware Turns Chrome and Edge Into Backdoors","og_description":"PEEP malware turns compromised Chrome and Edge sessions into backdoors for data theft and host commands. Learn how enterprises can respond.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-08T08:12:04+00:00","article_modified_time":"2026-09-09T09:05:30+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"PEEP Malware Turns Chrome and Edge Into Post-Compromise Backdoors","datePublished":"2026-09-08T08:12:04+00:00","dateModified":"2026-09-09T09:05:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/"},"wordCount":1309,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp","articleSection":["Malware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/","url":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/","name":"PEEP Malware Turns Chrome and Edge Into Backdoors","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp","datePublished":"2026-09-08T08:12:04+00:00","dateModified":"2026-09-09T09:05:30+00:00","description":"PEEP malware turns compromised Chrome and Edge sessions into backdoors for data theft and host commands. Learn how enterprises can respond.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/PEEP-Malware-Turns-Chrome-and-Edge-Into-Post-Compromise-Backdoor.jpeg?format=webp","width":1340,"height":754,"caption":"PEEP Malware Turns Chrome and Edge Into Post-Compromise Backdoor"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/peep-malware-chrome-edge-backdoor\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"PEEP Malware Turns Chrome and Edge Into Post-Compromise Backdoors"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1467","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1467"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1467\/revisions"}],"predecessor-version":[{"id":1474,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1467\/revisions\/1474"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1471"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1467"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1467"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}