VMTech
Discuss a project

China-Linked Groups Exploit Chrome and Windows Flaws to Deliver Malware

China-Linked Groups Exploit Chrome and Windows Flaws to Deliver Malware

Volexity has attributed a September 1, 2026 spear-phishing campaign against multiple non-governmental organisations to a China-linked cluster it tracks as UTA0560. The operation chained two Google Chrome flaws and one Microsoft Windows Advanced Local Procedure Call flaw to install GRIMWEDGE, a malicious JavaScript backdoor.

The three vulnerabilities are CVE-2026-85046, which provided arbitrary read and write access within the V8 sandbox; CVE-2026-87491, used to escape the browser sandbox; and CVE-2026-85880, used to inject code into the Chrome process and gain arbitrary code execution. Volexity said a second China-nexus actor, JungleBamboo, also known as APT31, used the same chain at roughly the same time.

Phishing route and staged exploitation

The UTA0560 emails urged recipients to follow a link to the website of a US-based university. The attackers abused a reflected cross-site scripting vulnerability on that legitimate site to redirect targets to attacker-controlled infrastructure hosting the multi-stage exploit chain, called BlueMoon.

The delivery site filtered out visitors who were not using Chrome on Windows. Its final exploit page embedded three Base64-encoded binary payloads in JavaScript: payloads for reconnaissance and fingerprinting, Windows kernel privilege escalation, and browser-process injection with payload download.

The campaign then delivered an executable called msgbox.exe. It extracts a legitimate Windows binary and a malicious DLL, wsc.dll, starting a DLL sideloading chain. The DLL requests a text file named after the profiled device hostname; that file is an MSI installer whose custom actions execute the obfuscated GRIMWEDGE backdoor.

Backdoor and credential-theft payloads

GRIMWEDGE polls its command-and-control server, ocr.opusaccel[.]top, and executes received instructions in memory through eval(). Its commands support system reconnaissance, directory listings and creation, file deletion and reading, process enumeration and termination, hidden command execution, and chunked file download.

Volexity said the malware has no built-in persistence, lateral movement or dedicated exfiltration capability beyond its file-read and upload functions. Nevertheless, those functions provide an initial foothold for surveying a host, retrieving selected files and deploying additional tools.

JungleBamboo used the same exploit chain to install SUPERSTOMP, which fetched LONGTALE, also called GemStone. LONGTALE masqueraded as a Google Gemini Chrome extension with ID ckiknalbeplpcpofpnabcnhjcegckfei. It can capture keystrokes and forms, steal cookies and sessions, take screenshots based on command-and-control-supplied keywords, and send collected browser data at approximately 30-second intervals.

The patch-gap risk

Although fixes for the two Chrome issues had reached the open-source Chromium codebase, they had not yet appeared in a stable Google Chrome release. That created a patch gap in which the bugs were addressed upstream but still functioned as zero-days against Chrome. Volexity noted that the near-simultaneous use of the chain by separate China-linked groups raises the possibility that the exploit was sold, shared or derived from reverse-engineering Chromium changes.

For businesses, the case makes browser update monitoring, phishing resistance and extension oversight operational priorities: upstream Chromium security fixes can signal material exposure before stable Chrome updates reach endpoints.

#cybersecurity#chromesecurity#threatintel#phishing
Open analytics
On the site 0 views
min read 4 15.09.2026
Instagram

China-Linked Groups Exploit Chrome and Windows Flaws to Deliver Malware

Open the post on Instagram ↗