A Chinese cybercriminal group, identified as UTA0560, has been linked to a spear-phishing campaign that exploits newly patched vulnerabilities in Google Chrome and Microsoft Windows. This campaign specifically targets non-governmental organizations, delivering a malicious JavaScript backdoor known as GRIMWEDGE. Security firm Volexity has been tracking this group and noted that the attacks began on September 1, 2026. The emails used in this campaign contained links that redirected victims to a legitimate, yet compromised, U.S.-based university website. These links exploited a cross-site scripting vulnerability, guiding users to infrastructure controlled by the attackers, which hosted a sophisticated multi-stage exploit chain. The exploit chain involves three vulnerabilities, two in Chrome and one in Windows Advanced Local Procedure Call. These are used to gain arbitrary read and write access, escape the browser sandbox, and execute arbitrary code. The GRIMWEDGE backdoor facilitates extensive reconnaissance and command execution on compromised hosts. In parallel, another Chinese group, JungleBamboo, also utilized the same exploit chain to deploy a credential-stealing Chrome extension called LONGTALE. This extension masquerades as a legitimate Google Gemini extension to avoid detection. The simultaneous use of this exploit chain by multiple actors suggests it might have been sold or shared after reverse-engineering Chromium source code changes. A significant concern is the patch gap, where vulnerabilities fixed in the Chromium codebase were not yet included in a stable release of Chrome, creating an opportunity for attackers to exploit these zero-days. This situation highlights the risks associated with patch gaps and the need for ongoing vigilance in cybersecurity.