Interestana
Home/News/China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain

A Chinese threat actor, identified by the moniker UTA0560, has been linked to a sophisticated spear-phishing campaign that leveraged a chain of recently patched zero-day vulnerabilities affecting both Google Chrome and Microsoft Windows. This campaign, which commenced on September 1, 2026, was designed to deliver a malicious JavaScript backdoor known as GRIMWEDGE. Security researchers at Volexity, who are actively tracking this threat cluster, reported these findings. The primary targets of this attack were multiple non-governmental organizations (NGOs), indicating a potential focus on intelligence gathering or disruption within the humanitarian and advocacy sectors. The exploitation chain began with a compromised website, which served as the initial vector for delivering the malicious payload to unsuspecting users. Once a target visited the compromised site using a vulnerable version of Google Chrome, the attackers could exploit a zero-day vulnerability within the browser. This initial exploit would then pave the way for a second zero-day exploit targeting the Microsoft Windows operating system. This dual exploitation allowed the attackers to gain a foothold on the victim's system with elevated privileges, bypassing standard security measures. The GRIMWEDGE backdoor, once deployed, provides the attackers with extensive capabilities. These include the ability to execute arbitrary commands, download and upload files, and potentially exfiltrate sensitive data from the compromised systems. The use of a JavaScript backdoor offers flexibility and stealth, as JavaScript is an integral part of web browsing and can be difficult to distinguish from legitimate browser activity. Volexity's analysis suggests that UTA0560 has been active for some time, employing various tactics and techniques to achieve its objectives. The specific targeting of NGOs raises concerns about the motives behind these attacks, which could range from espionage to disrupting the operations of organizations involved in sensitive political or social issues. The patching of these specific zero-day vulnerabilities by Google and Microsoft indicates that the threat actors were operating with novel exploits that had not yet been publicly disclosed or addressed by security vendors. This highlights the persistent threat posed by advanced persistent threat (APT) groups who are capable of discovering and weaponizing zero-day vulnerabilities before they are mitigated. The incident underscores the critical importance of timely security patching and the need for robust endpoint detection and response (EDR) solutions to identify and neutralize such advanced threats. The attribution to a China-linked threat actor aligns with previous intelligence reports detailing state-sponsored cyber espionage activities originating from China, often targeting organizations involved in geopolitical or economic interests. The GRIMWEDGE backdoor's capabilities suggest a focus on persistent access and data exfiltration, consistent with the objectives of nation-state actors.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next