A Chinese threat actor tracked as UTA0560 used spear-phishing and a Chrome-Windows exploit chain to deliver the GRIMWEDGE JavaScript backdoor to NGOs. Around the same time, JungleBamboo (APT31) used the same chain to deploy SUPERSTOMP and the LONGTALE credential-stealing Chrome extension. #UTA0560 #GRIMWEDGE #JungleBamboo #APT31 #LONGTALE #SUPERSTOMP #Chrome #Windows #BlueMoon
Keypoints
- UTA0560 targeted NGOs with spear-phishing emails on September 1, 2026.
- The attack abused a reflected XSS flaw on a university website to launch the exploit chain.
- The chain combined CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to run code in Chrome and Windows.
- GRIMWEDGE provided reconnaissance, file and process management, command execution, and payload delivery.
- JungleBamboo, also known as APT31, used the same chain to deploy SUPERSTOMP and the LONGTALE Chrome extension.
Read More: https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html