China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor tracked as UTA0560 used spear-phishing and a Chrome-Windows exploit chain to deliver the GRIMWEDGE JavaScript backdoor to NGOs. Around the same time, JungleBamboo (APT31) used the same chain to deploy SUPERSTOMP and the LONGTALE credential-stealing Chrome extension. #UTA0560 #GRIMWEDGE #JungleBamboo #APT31 #LONGTALE #SUPERSTOMP #Chrome #Windows #BlueMoon

Keypoints

  • UTA0560 targeted NGOs with spear-phishing emails on September 1, 2026.
  • The attack abused a reflected XSS flaw on a university website to launch the exploit chain.
  • The chain combined CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to run code in Chrome and Windows.
  • GRIMWEDGE provided reconnaissance, file and process management, command execution, and payload delivery.
  • JungleBamboo, also known as APT31, used the same chain to deploy SUPERSTOMP and the LONGTALE Chrome extension.

Read More: https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html