China-Linked Hackers Deploy GRIMWEDGE via Chrome-Windows Zero-Day Chain

1 min read
Source: The Hacker News
China-Linked Hackers Deploy GRIMWEDGE via Chrome-Windows Zero-Day Chain
Photo: The Hacker News
TL;DR

A China-nexus group (UTA0560) targeted NGOs with a spear-phishing campaign delivering a three-CVE Chrome/Windows zero-day chain (BlueMoon) to install the GRIMWEDGE backdoor. The chain uses CVE-2026-85046 and CVE-2026-87491 to escape the Chrome sandbox and CVE-2026-85880 for code execution, culminating in a loader (msgbox.exe) that fetches a malicious DLL (wsc.dll) via DLL sideloading and establishes a persistent command loop to execute C2 instructions from ocr.opusaccel.top. The backdoor supports system discovery, file and process management, and in-memory execution, with a payload rollout that includes an MSI-based obfuscated JavaScript backdoor. A second actor, JungleBamboo (APT31), used the same chain to deploy LONGTALE/GemStone, a credential-stealing Chrome extension. The campaign underscored a patch-gap risk between Chromium fixes and Chrome releases, creating an exploitation window before official patches arrived.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News