
China-Linked Hackers Deploy GRIMWEDGE via Chrome-Windows Zero-Day Chain
A China-nexus group (UTA0560) targeted NGOs with a spear-phishing campaign delivering a three-CVE Chrome/Windows zero-day chain (BlueMoon) to install the GRIMWEDGE backdoor. The chain uses CVE-2026-85046 and CVE-2026-87491 to escape the Chrome sandbox and CVE-2026-85880 for code execution, culminating in a loader (msgbox.exe) that fetches a malicious DLL (wsc.dll) via DLL sideloading and establishes a persistent command loop to execute C2 instructions from ocr.opusaccel.top. The backdoor supports system discovery, file and process management, and in-memory execution, with a payload rollout that includes an MSI-based obfuscated JavaScript backdoor. A second actor, JungleBamboo (APT31), used the same chain to deploy LONGTALE/GemStone, a credential-stealing Chrome extension. The campaign underscored a patch-gap risk between Chromium fixes and Chrome releases, creating an exploitation window before official patches arrived.