← Back to blog

China-Linked Hackers Weaponize Chrome-Windows Zero-Day Chain

A Chinese threat actor exploited recently patched vulnerabilities in Chrome and Windows to deploy the GRIMWEDGE backdoor. The campaign targeted NGOs in a spear-phishing operation.

TL;DR

  • Chinese hackers used a zero-day chain in Chrome and Windows to deliver GRIMWEDGE malware.
  • The attacks occurred on September 1, 2026, targeting multiple NGOs.
  • Volexity tracks the group as UTA0560.
  • GRIMWEDGE is a JavaScript-based backdoor used for persistent access.
  • Organizations should patch Chrome and Windows immediately to mitigate risk.

A sophisticated cyberattack has emerged from China-linked threat actors who leveraged a chain of zero-day vulnerabilities in Google Chrome and Microsoft Windows. These exploits were used to deliver a JavaScript backdoor known as GRIMWEDGE in a targeted spear-phishing campaign.

According to Volexity, which has designated the actor as UTA0560, the attacks took place on September 1, 2026, and focused on several non-governmental organizations. The use of zero-day flaws highlights the advanced nature of the campaign and underscores the importance of timely patching and proactive defense measures.

Attack Vector and Exploitation

  • The attack chain began with a spear-phishing attempt exploiting a zero-day in Google Chrome.
  • A subsequent Windows vulnerability was used to escalate privileges and maintain persistence.
  • Both vulnerabilities had been recently patched prior to the attack, suggesting rapid exploitation of newly disclosed flaws.
  • UTA0560 leveraged these flaws to deploy GRIMWEDGE, a lightweight JavaScript backdoor.

GRIMWEDGE Backdoor Capabilities

  • GRIMWEDGE functions as a stealthy backdoor written in JavaScript for cross-platform compatibility.
  • It enables remote command execution, data exfiltration, and lateral movement within compromised networks.
  • The backdoor communicates with attacker-controlled infrastructure using encrypted channels.
  • Its design avoids detection by traditional signature-based security tools.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.