A Chinese cybercriminal group, identified as UTA0560, has been linked to a spear-phishing campaign that exploits newly patched vulnerabilities in Google Chrome and Microsoft Windows. This campaign specifically targets non-governmental organizations, delivering a malicious JavaScript backdoor known as GRIMWEDGE. Security firm Volexity has been tracking this group and noted that the attacks began on September 1, 2026. The emails used in this campaign contained links that redirected victims to a legitimate, yet compromised, U.S.-based university website. These links exploited a cross-site scripting vulnerability, guiding users to infrastructure controlled by the attackers, which hosted a sophisticated multi-stage exploit chain. The exploit chain involves three vulnerabilities, two in Chrome and one in Windows Advanced Local Procedure Call. These are used to gain arbitrary read and write access, escape the browser sandbox, and execute arbitrary code. The GRIMWEDGE backdoor facilitates extensive reconnaissance and command execution on compromised hosts. In parallel, another Chinese group, JungleBamboo, also utilized the same exploit chain to deploy a credential-stealing Chrome extension called LONGTALE. This extension masquerades as a legitimate Google Gemini extension to avoid detection. The simultaneous use of this exploit chain by multiple actors suggests it might have been sold or shared after reverse-engineering Chromium source code changes. A significant concern is the patch gap, where vulnerabilities fixed in the Chromium codebase were not yet included in a stable release of Chrome, creating an opportunity for attackers to exploit these zero-days. This situation highlights the risks associated with patch gaps and the need for ongoing vigilance in cybersecurity.
Chinese Hackers Exploit Unpatched Flaws in Chrome and Windows to Deploy GRIMWEDGE Backdoor
China-linked actors chained Chrome and Windows flaws to deploy GRIMWEDGE JavaScript backdoor against NGOs; validate browser and OS patching.
Executive Summary
Chinese hackers have exploited unpatched Chrome and Windows vulnerabilities to deploy a malicious backdoor targeting NGOs. The patch gap allowed attackers to leverage these zero-days before official patches were released.
Actionable Insights
- Regularly update all software to the latest versions to close patch gaps.
- Implement robust email filtering to detect and block spear-phishing attempts.
- Monitor network traffic for signs of unauthorized access or exploitation attempts.
Original source
thehackernews.com

