Volexity uncovered spear-phishing campaigns by UTA0560 and JungleBamboo that abused a Chrome zero-day exploit chain to target NGOs and other victims through malicious links and patched-but-unreleased Chromium flaws. UTA0560 used the chain to deploy GRIMWEDGE, while JungleBamboo used it to install SUPERSTOMP and the LONGTALE Chrome extension for credential theft and surveillance. #UTA0560 #JungleBamboo #GRIMWEDGE #SUPERSTOMP #LONGTALE #CVE-2026-85046 #CVE-2026-85880 #CVE-2026-87491
Keypoints
- Volexity detected spear-phishing campaigns on September 1, 2026, targeting NGOs and other victims with links leading to a Chrome exploit chain.
- The exploit chain abused a reflected XSS redirect on a US-based university site and then launched a multi-stage Chrome/Windows attack.
- CVE-2026-85046 in Chromeâs V8 engine, CVE-2026-87491 in WebAssembly, and CVE-2026-85880 in the Windows kernel were chained together to escape sandbox protections.
- UTA0560 delivered the GRIMWEDGE JScript backdoor after exploitation, enabling reconnaissance, command execution, file operations, and payload delivery.
- JungleBamboo reused the same exploit chain but deployed SUPERSTOMP to install the LONGTALE Chrome extension instead of GRIMWEDGE.
- LONGTALE focused on credential theft, keylogging, cookie/session capture, screenshots, and periodic exfiltration rather than remote code execution.
- Volexity assesses the exploit chain may have been shared or sold, and notes that patch delays in Chrome created a window for active exploitation.
MITRE Techniques
- [T1566.002 ] Spearphishing Link â Victims received emails with links that redirected them into the exploit chain (âthe emails contained a message encouraging the users to click a linkâ).
- [T1189 ] Drive-by Compromise â Clicking the link led to attacker-controlled exploit infrastructure that delivered the browser exploit (âredirecting recipients to threat-actor-controlled infrastructure hosting a multi-stage exploit chainâ).
- [T1203 ] Exploitation for Client Execution â The Chrome exploit chain executed malicious code when the victim opened the crafted page (âbrowser executes malicious code contained within the exploitâ).
- [T1068 ] Exploitation for Privilege Escalation â A Windows kernel flaw was used to escape sandbox restrictions and elevate privileges (âexploits a third vulnerability in the Windows kernelâ).
- [T1204.001 ] User Execution: Malicious Link â The attack depended on the user clicking the phishing URL (âUpon clicking the URL, the browser redirectedâ).
- [T1055 ] Process Injection â The final shellcode injected code into the Chrome browser process (âcall the Windows API function CreateProcessA to execute a commandâ).
- [T1106 ] Native API â The shellcode used Windows APIs such as CreateProcessA to launch the next stage (âcalls the Windows API function CreateProcessAâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Wsc.dll created a recurring scheduled task for persistence (âcreating a scheduled task named âWindows Scheduled Systemââ).
- [T1027 ] Obfuscated Files or Information â The JavaScript loader and payloads were obfuscated or embedded as inert data (âobfuscated JavaScript loaderâ, âscript type=âtext/plainââ).
- [T1059.007 ] Command and Scripting Interpreter: JavaScript â GRIMWEDGE executed as JScript within msiexec.exe (âa backdoor executing entirely in memory as an eval()âd stringâ).
- [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell â The final stage used cmd.exe to download and execute payloads (âcmd.exe /c curl ⌠&& â%TEMP%msgbox.exeââ).
- [T1105 ] Ingress Tool Transfer â Additional payloads were downloaded from attacker infrastructure (âdownload the next-stage loader from the C2 serverâ).
- [T1218.010 ] System Binary Proxy Execution: Regsvr32 â The article describes sideloading via a legitimate binary and malicious DLL chain; if interpreted as binary proxy execution, the legitimate EXE loaded the malicious DLL (âsideloaded via the legitimate binary contained in msgbox.exeâ).
Indicators of Compromise
- [Domains ] Phishing, exploit hosting, and C2 infrastructure â cloud.shinewrist[.]net, ocr[.]opusaccel[.]top, and 2 more domains
- [Domains ] JungleBamboo phishing and extension infrastructure â msbenefit[.]com, gitprogram[.]com
- [IPs ] Hosting for UTA0560 infrastructure â 206[.]166[.]251[.]164
- [URLs ] Phishing and payload delivery URLs â hxxps://photos.msbenefit[.]com/fa/t3, hxxps://proof.gitprogram[.]com/a4/j8, and hxxps://xyz0102.gitprogram[.]com/a001
- [Email addresses ] Phishing sender used by UTA0560 â ircribbin77[@]hotmail[.]com
- [File names ] Exploit and payload files â Files1.html, react.min.js, page.html, and msgbox.exe
- [File hashes ] Sample hashes for exploit and malware files â d17053557bb90298f7b115432b4820a248fdbe678bca31721529b1f51a82343b, 337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d, and 3 more hashes
- [Extension ID ] Malicious Chrome extension identifier â ckiknalbeplpcpofpnabcnhjcegckfei