🔐
Security 📅 2026-09-08 · 08:01 AM IST ⏱ 3 min read

New Browser Hijacking Tool Puts Corporate Leaders at Risk Through Fake Support Calls

Attackers use disguised browser add-ons to steal Microsoft 365 data from executives in targeted campaigns.

Attackers Deploy Hidden Browser Weapon Against Business Leaders

Security experts have uncovered a dangerous new threat targeting high-level employees at companies worldwide. The attack combines social engineering with sophisticated software designed to steal sensitive business information stored in Microsoft 365 accounts. Criminals pose as IT support staff, convincing victims to install what appears to be a legitimate browser extension—but actually contains malicious code that grants attackers complete access to corporate data.

The toolkit, referred to as PEEP by researchers, operates by hiding inside what looks like an innocent bookmarks manager for Chrome and Edge browsers. Once installed, it transforms into a remote access tool that thieves can control from afar. The attackers then demand ransom payments, threatening to expose or destroy the stolen information unless companies pay up.

What This Means for Business Security

This represents a significant shift in how criminals target organizations. Rather than trying to break through company firewalls from the outside, attackers are now using psychology and deception to get employees to voluntarily install the dangerous software. Think of it like someone pretending to be a locksmith to gain entry to a building—except the "building" is your entire digital workspace.

The attack's effectiveness lies in its two-part approach. First, attackers make convincing phone calls claiming to be from your company's IT department. They create a sense of urgency by mentioning a security issue or required update. When the employee agrees to help, they're directed to download and install the fake extension. Second, once installed, the tool gives criminals the keys to the kingdom—access to emails, files, calendars, and shared documents containing business secrets and sensitive information.

Why You Should Care

If you work in leadership, finance, human resources, or any department handling confidential information, you're likely a target. These attacks specifically hunt for senior executives and decision-makers who have access to valuable data and company funds. The damage extends beyond money—exposed information can harm business relationships, damage reputation, and lead to regulatory violations.

Even companies that pay the ransom face continued risk, as attackers may have already shared stolen data or may return for future extortion attempts.

What You Can Do

The golden rule: Never install software based on a phone call, no matter how legitimate it sounds.

Protect yourself by following these practical steps:

Organizations should also implement multi-factor authentication on all Microsoft 365 accounts and train employees to recognize social engineering tactics before they fall victim.

As remote work and cloud services become standard, staying vigilant against these psychological attacks is just as important as maintaining strong passwords.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →