China-Linked Hackers Deploy GRIMWEDGE via Chrome-Windows Zero-Day Chain

A China-nexus group (UTA0560) targeted NGOs with a spear-phishing campaign delivering a three-CVE Chrome/Windows zero-day chain (BlueMoon) to install the GRIMWEDGE backdoor. The chain uses CVE-2026-85046 and CVE-2026-87491 to escape the Chrome sandbox and CVE-2026-85880 for code execution, culminating in a loader (msgbox.exe) that fetches a malicious DLL (wsc.dll) via DLL sideloading and establishes a persistent command loop to execute C2 instructions from ocr.opusaccel.top. The backdoor supports system discovery, file and process management, and in-memory execution, with a payload rollout that includes an MSI-based obfuscated JavaScript backdoor. A second actor, JungleBamboo (APT31), used the same chain to deploy LONGTALE/GemStone, a credential-stealing Chrome extension. The campaign underscored a patch-gap risk between Chromium fixes and Chrome releases, creating an exploitation window before official patches arrived.
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE The Hacker News
- Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days Proofpoint
- Chinese espionage groups swarm to exploit triple-link chain of zero-days CyberScoop
- New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws BleepingComputer
- Four groups caught using the same Chrome and Windows exploit kit Ars Technica
Want the full story? Read the original reporting
Read on The Hacker News