INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Volexity Exploits Chrome Zero-Day in GRIMWEDGE Attack
| 2026-09-22 18:47 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat group UTA0565, linked to China-aligned activities and exploiting vulnerabilities in Chrome and Microsoft, has been spotted across multiple campaigns. This coordinated effort suggests a large-scale exploitation kit shared among multiple groups within the Chinese computer network. Researchers at Volexity have identified similar tactics used by other threat actors, including JungleBamboo (aka APT31), which deployed a loader named SUPERSTOMP to install LONGTALE, a Chrome extension known as GemStone. This near-simultaneous use of the same exploit chain in China raises concerns that it may have been sold or made available to them by the exploit developer after possibly reverse-engineering the changes in the Chromium source code.
Technical Mitigations AI-generated
* Use up-to-date and patched versions of Google Chrome and Microsoft Windows to prevent exploitation of the CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 zero-day vulnerabilities.
* Implement a web application firewall (WAF) or content security policy (CSP) to block malicious JavaScript code from being executed on websites that may be targeted by UTA0565.
* Regularly scan for and remove malware, including the "CLEANGULP" malware family tracked by Volexity, which is known to be used in various threat groups, including those attributed to GRIMWEDGE.
* Use a secure email client or service with built-in phishing protection to prevent UTA0565 from sending phishing emails that target multiple non-governmental organizations (NGOs) and other entities.
* Monitor for suspicious activity on websites targeted by UTA0565 and take prompt action if necessary, such as blocking access to the website or reporting it to the relevant authorities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
oc•••••.top
ms•••••.exe
ws•••••.dll
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-87491CVE-2026-87491
CVE-2026-85046CVE-2026-85046
CVE-2026-85880CVE-2026-85880
Target & Sectors
HK
CN
mediamedia
governmentgovernment
Incident Timeline
between Sept. 3 and 4
The China-aligned threat group UTA0565 exploited vulnerabilities in Chrome and Microsoft between September 3 and 4.
Click on any entity below to view its context and source!
organisation
UTA0565
The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said.
organisation
Chrome
The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said.
September 1, 2026
Threat actors exploited vulnerabilities in Chrome and Microsoft to target non-governmental organizations on September 1, 2026.
Sept. 8
Threat actors exploited remote-code execution defects in the JavaScript engine for Chromium-based browsers to target Windows systems.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85046
The vulnerabilities include:
CVE-2026-85046
and
CVE-2026-87491
, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and
CVE-2026-85880
, a privilege-escalation zero-day that
Microsoft disclosed Sept. 8
in Windows Advanced Local Procedure Call.
vulnerability
CVE-2026-87491
The vulnerabilities include:
CVE-2026-85046
and
CVE-2026-87491
, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and
CVE-2026-85880
, a privilege-escalation zero-day that
Microsoft disclosed Sept. 8
in Windows Advanced Local Procedure Call.
vulnerability
CVE-2026-85880
The vulnerabilities include:
CVE-2026-85046
and
CVE-2026-87491
, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and
CVE-2026-85880
, a privilege-escalation zero-day that
Microsoft disclosed Sept. 8
in Windows Advanced Local Procedure Call.
infrastructure
Windows
The vulnerabilities include:
CVE-2026-85046
and
CVE-2026-87491
, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and
CVE-2026-85880
, a privilege-escalation zero-day that
Microsoft disclosed Sept. 8
in Windows Advanced Local Procedure Call.
tactic
T1059.007 - JavaScript
The vulnerabilities include:
CVE-2026-85046
and
CVE-2026-87491
, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and
CVE-2026-85880
, a privilege-escalation zero-day that
Microsoft disclosed Sept. 8
in Windows Advanced Local Procedure Call.
organisation
Chromium
The vulnerabilities include:
CVE-2026-85046
and
CVE-2026-87491
, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and
CVE-2026-85880
, a privilege-escalation zero-day that
Microsoft disclosed Sept. 8
in Windows Advanced Local Procedure Call.
organisation
Windows Advanced Local Procedure Call
The vulnerabilities include:
CVE-2026-85046
and
CVE-2026-87491
, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and
CVE-2026-85880
, a privilege-escalation zero-day that
Microsoft disclosed Sept. 8
in Windows Advanced Local Procedure Call.
2026/09/08
Threat actors exploited a known vulnerability in Chrome and Microsoft's security updates to target China-aligned groups before official patches were released.
Click on any entity below to view its context and source!
organisation
Google
Given that Chrome relied on a four-week release cycle for major milestone releases until last week (it's
every two weeks now
), it's possible the attackers sought to move quickly before the exploitation window closed and the official patches arrived from Google.
2026/09/22
Chinese threat actors exploited recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.
Click on any entity below to view its context and source!
organisation
Microsoft
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects.
organisation
the Center for American Progress
The group spoofed domains impersonating the Center for American Progress and China Digital Times in other phishing emails.
organisation
China Digital Times
The group spoofed domains impersonating the Center for American Progress and China Digital Times in other phishing emails.
infrastructure
Windows
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called
GRIMWEDGE
.
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE.
"
The near-simultaneous use of the same Chrome-Windows chain by multiple threat actors in China has raised the possibility that it may have been sold, or made available, to them by the exploit developer after possibly reverse-engineering the changes in the Chromium source code.
The final exploit page embeds three binary payloads as Base64-encoded strings within JavaScript -
p1
, shellcode that reflectively loads a DLL to conduct host reconnaissance and fingerprinting
p2
, shellcode that reflectively loads a DLL to facilitate Windows kernel privilege escalation
pp
, shellcode to perform browser process injection and payload download
In the case of UTA0560, the next-stage payload is an executable named "msgbox.exe," which serves as a loader responsible for extracting from itself a legitimate Windows binary and a malicious DLL ("wsc.dll") to initiate a DLL sideloading chain.
"
The exploit chain, as
previously highlighted
by Proofpoint, involves three separate flaws – two in Chrome and one in Windows Advanced Local Procedure Call (ALPC).
The threat actor is said to have leveraged this flaw to trigger the zero-day exploit chain, also called BlueMoon, to deliver the malware, while filtering out systems not using Chrome on Windows to visit the URL.
organisation
Google Chrome
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called
GRIMWEDGE
.
organisation
Microsoft Windows
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called
GRIMWEDGE
.
organisation
JungleBamboo
"
Volexity said it also observed a second China-nexus threat actor known as JungleBamboo (aka APT31) using the same exploit chain around the same time to deploy a loader named SUPERSTOMP, which then installs LONGTALE, a credential-stealing Chrome extension also referred to as
GemStone
, from a remote server.
organisation
SUPERSTOMP
"
Volexity said it also observed a second China-nexus threat actor known as JungleBamboo (aka APT31) using the same exploit chain around the same time to deploy a loader named SUPERSTOMP, which then installs LONGTALE, a credential-stealing Chrome extension also referred to as
GemStone
, from a remote server.
organisation
LONGTALE
"
Volexity said it also observed a second China-nexus threat actor known as JungleBamboo (aka APT31) using the same exploit chain around the same time to deploy a loader named SUPERSTOMP, which then installs LONGTALE, a credential-stealing Chrome extension also referred to as
GemStone
, from a remote server.
organisation
GemStone
"
Volexity said it also observed a second China-nexus threat actor known as JungleBamboo (aka APT31) using the same exploit chain around the same time to deploy a loader named SUPERSTOMP, which then installs LONGTALE, a credential-stealing Chrome extension also referred to as
GemStone
, from a remote server.
organisation
Chrome-Windows
"
The near-simultaneous use of the same Chrome-Windows chain by multiple threat actors in China has raised the possibility that it may have been sold, or made available, to them by the exploit developer after possibly reverse-engineering the changes in the Chromium source code.
organisation
DLL
The final exploit page embeds three binary payloads as Base64-encoded strings within JavaScript -
p1
, shellcode that reflectively loads a DLL to conduct host reconnaissance and fingerprinting
p2
, shellcode that reflectively loads a DLL to facilitate Windows kernel privilege escalation
pp
, shellcode to perform browser process injection and payload download
In the case of UTA0560, the next-stage payload is an executable named "msgbox.exe," which serves as a loader responsible for extracting from itself a legitimate Windows binary and a malicious DLL ("wsc.dll") to initiate a DLL sideloading chain.
organisation
MSI
The text file is an MSI installer designed to execute an obfuscated JavaScript backdoor contained within the MSI custom actions.
organisation
Chromium
In other words, the upstream patches created an unusual case of two N-day bugs that were addressed in Chromium, but not in Chrome.
organisation
Chrome
This, in turn, made them zero-days against Chrome.
organisation
GRIMWEDGE
UTA0560 has been observed relying on this attack method to deploy GRIMWEDGE, which facilitates host reconnaissance, file and process management, command execution, and payload delivery capabilities.
organisation
PID
It's equipped to parse the following commands -
Info
, to perform system reconnaissance
Dir
, to fetch a directory listing
Mkdir
, to create a directory
Del
, to delete a file
Tasklist
, to enumerate running processes
Taskkill
, to kill a process by PID
Type
, to read a file up to 5 MB
Run
, to execute a command within a hidden window
Upload (chunk)
, to get a Base64-encoded chunk from the C2 server and append to an in-memory buffer
Upload (commit)
, to save the accumulated buffer to disk as the final file
"The code has no built-in persistence, lateral movement, or exfiltration mechanism beyond the file-read and upload commands," the researchers said.
organisation
Upload
It's equipped to parse the following commands -
Info
, to perform system reconnaissance
Dir
, to fetch a directory listing
Mkdir
, to create a directory
Del
, to delete a file
Tasklist
, to enumerate running processes
Taskkill
, to kill a process by PID
Type
, to read a file up to 5 MB
Run
, to execute a command within a hidden window
Upload (chunk)
, to get a Base64-encoded chunk from the C2 server and append to an in-memory buffer
Upload (commit)
, to save the accumulated buffer to disk as the final file
"The code has no built-in persistence, lateral movement, or exfiltration mechanism beyond the file-read and upload commands," the researchers said.
data_breach
5 MB Run
It's equipped to parse the following commands -
Info
, to perform system reconnaissance
Dir
, to fetch a directory listing
Mkdir
, to create a directory
Del
, to delete a file
Tasklist
, to enumerate running processes
Taskkill
, to kill a process by PID
Type
, to read a file up to 5 MB
Run
, to execute a command within a hidden window
Upload (chunk)
, to get a Base64-encoded chunk from the C2 server and append to an in-memory buffer
Upload (commit)
, to save the accumulated buffer to disk as the final file
"The code has no built-in persistence, lateral movement, or exfiltration mechanism beyond the file-read and upload commands," the researchers said.
organisation
Run and Upload
"The backdoor provides an initial foothold on a compromised host sufficient enough for UTA0560 to survey the host, retrieve files of interest, and deploy additional tooling via the Run and Upload commands.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
The vulnerabilities include:
CVE-2026-85046
and
CVE-2026-87491
, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and
CVE-2026-85880
, a privilege-escalation zero-day that
Microsoft disclosed Sept. 8
in Windows Advanced Local Procedure Call.
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE.
"
The near-simultaneous use of the same Chrome-Windows chain by multiple threat actors in China has raised the possibility that it may have been sold, or made available, to them by the exploit developer after possibly reverse-engineering the changes in the Chromium source code.
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called
GRIMWEDGE
.
The final exploit page embeds three binary payloads as Base64-encoded strings within JavaScript -
p1
, shellcode that reflectively loads a DLL to conduct host reconnaissance and fingerprinting
p2
, shellcode that reflectively loads a DLL to facilitate Windows kernel privilege escalation
pp
, shellcode to perform browser process injection and payload download
In the case of UTA0560, the next-stage payload is an executable named "msgbox.exe," which serves as a loader responsible for extracting from itself a legitimate Windows binary and a malicious DLL ("wsc.dll") to initiate a DLL sideloading chain.
"
The exploit chain, as
previously highlighted
by Proofpoint, involves three separate flaws – two in Chrome and one in Windows Advanced Local Procedure Call (ALPC).
The threat actor is said to have leveraged this flaw to trigger the zero-day exploit chain, also called BlueMoon, to deliver the malware, while filtering out systems not using Chrome on Windows to visit the URL.
Metrics
data_breach
5
Mb Run
It's equipped to parse the following commands -
Info
, to perform system reconnaissance
Dir
, to fetch a directory listing
Mkdir
, to create a directory
Del
, to delete a file
Tasklist
, to enumerate running processes
Taskkill
, to kill a process by PID
Type
, to read a file up to 5 MB
Run
, to execute a command within a hidden window
Upload (chunk)
, to get a Base64-encoded chunk from the C2 server and append to an in-memory buffer
Upload (commit)
, to save the accumulated buffer to disk as the final file
"The code has no built-in persistence, lateral movement, or exfiltration mechanism beyond the file-read and upload commands," the researchers said.
Intelligence Sources
The Hacker News
2026-09-15
CyberScoop
2026-09-22
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-23T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
21x
organisation
Identified Entity
Microsoft
entity
8x
tactic
Cyber Operation Type
Phishing
tactic
4x
timeline
Temporal Reference
Sept. 8
date
3x
vulnerability
Exploited CVE
CVE-2026-85046
cve
2x
target region
Target Country
China
country
2x
industry
Targeted Sector
Government
sector
2x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
2x
general metric
Cve-2026
87,491
cve-2026
Contextual Telemetry
Context Block
4 METRICS
source region
Origin Country
China
country
infrastructure
Affected Product
Windows
software
data breach
Mb Run
5
mb run
general metric
Second
30
second
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.