A threat actor, identified as UTA0560 by Volexity, has been linked to a spear-phishing campaign exploiting recently patched vulnerabilities in Google Chrome and Microsoft Windows. This campaign aims to deliver a malicious JavaScript backdoor known as GRIMWEDGE. The attacks targeted several non-governmental organizations (NGOs) on September 1, 2026. The phishing emails contained links leading to a U.S.-based university's website, exploiting a reflected cross-site scripting (XSS) vulnerability to redirect recipients to a threat actor-controlled infrastructure, initiating a multi-stage exploit chain. The exploit chain, highlighted by Proofpoint, involves three distinct vulnerabilities: two in Chrome and one in Windows Advanced Local Procedure Call (ALPC). The attack begins by exploiting CVE-2026-85046 to gain arbitrary read/write access within the V8 sandbox, followed by escaping the browser sandbox via CVE-2026-87491, and finally using CVE-2026-85880 to inject code into the Chrome browser process for arbitrary code execution. UTA0560 uses this method to deploy GRIMWEDGE, which facilitates host reconnaissance, file and process management, command execution, and payload delivery. The spear-phishing emails persuade recipients to click on links pointing to legitimate websites with reflective XSS vulnerabilities. The threat actor uses this flaw to trigger the zero-day exploit chain, dubbed BlueMoon, to deliver the malware while filtering out systems not using Chrome on Windows. The final exploit page embeds three binary payloads within JavaScript, which are Base64-encoded strings. These payloads include shellcode for host reconnaissance, Windows kernel privilege escalation, and browser process injection. Once the initial payload is executed, it drops an executable named "msgbox.exe," which acts as a loader to extract a legitimate Windows binary and a malicious DLL ("wsc.dll") to start a DLL sideloading chain. The DLL contacts the same server to fetch a text file named after the device's hostname, obtained during profiling. This text file is an MSI installer that executes an obfuscated JavaScript backdoor, GRIMWEDGE, which enters a persistent command loop to communicate with a command-and-control (C2) server for further instructions. GRIMWEDGE is equipped to perform various tasks, including system reconnaissance, directory listing, file deletion, process enumeration and termination, file reading, command execution, and file upload. Although the backdoor lacks built-in persistence, lateral movement, or exfiltration mechanisms beyond file-read and upload commands, it provides an initial foothold on compromised hosts. This allows UTA0560 to survey the host, retrieve files of interest, and deploy additional tools via the Run and Upload commands. Volexity also identified another s threat actor, JungleBamboo (aka APT31), using the same exploit chain to deploy a loader named SUPERSTOMP, which installs LONGTALE, a credential-stealing Chrome extension. LONGTALE masquerades as a Google Gemini Chrome extension to evade detection and supports features like keylogging, form capture, cookie and session theft, screenshot capture, and bulk exfiltration of data to a C2 server. Despite lacking a remote code execution command, LONGTALE's extensive information-theft capabilities suffice for JungleBamboo's credential theft and surveillance objectives. The simultaneous use of the same Chrome-Windows exploit chain by multiple threat actors suggests it may have been sold or made available to them by the exploit developer. This situation highlights a patch gap, where fixes for Chrome vulnerabilities were pushed to the Chromium codebase but not incorporated into a stable release version of Google Chrome, creating zero-day vulnerabilities. The attackers likely sought to exploit this window before Google's official patches were released. Volexity emphasizes the risk posed by patch-gap vulnerabilities, which provide an additional time window for threat actors to exploit. As large language models become more effective for rapid vulnerability research and exploit development, the potential for such exploitation campaigns increases. The article concludes by encouraging readers to follow Volexity on Google News, Twitter, and LinkedIn for more exclusive content.
Cybersecurity
Hackers Exploit Chrome Zero Day Chain to Deploy GRIMWEDGE
Cyber RTSeptember 15, 20263 min read

A threat actor, UTA0560, launched a spear-phishing campaign exploiting patched flaws in Google Chrome and Microsoft Windows to deliver the GRIMWEDGE backdoor. Targeting NGOs, the attack used a reflected XSS vulnerability to trigger a zero-day exploit chain, BlueMoon, for malware delivery. Another actor, JungleBamboo, used the same chain to deploy the LONGTALE credential-stealing Chrome extension. Patch gaps in Chrome facilitated these exploits.


