China-Linked Hackers Weaponize Chrome-Windows Zero-Day Chain
A Chinese threat actor exploited recently patched vulnerabilities in Chrome and Windows to deploy the GRIMWEDGE backdoor. The campaign targeted NGOs in a spear-phishing operation.
TL;DR
- Chinese hackers used a zero-day chain in Chrome and Windows to deliver GRIMWEDGE malware.
- The attacks occurred on September 1, 2026, targeting multiple NGOs.
- Volexity tracks the group as UTA0560.
- GRIMWEDGE is a JavaScript-based backdoor used for persistent access.
- Organizations should patch Chrome and Windows immediately to mitigate risk.
A sophisticated cyberattack has emerged from China-linked threat actors who leveraged a chain of zero-day vulnerabilities in Google Chrome and Microsoft Windows. These exploits were used to deliver a JavaScript backdoor known as GRIMWEDGE in a targeted spear-phishing campaign.
According to Volexity, which has designated the actor as UTA0560, the attacks took place on September 1, 2026, and focused on several non-governmental organizations. The use of zero-day flaws highlights the advanced nature of the campaign and underscores the importance of timely patching and proactive defense measures.
Attack Vector and Exploitation
- The attack chain began with a spear-phishing attempt exploiting a zero-day in Google Chrome.
- A subsequent Windows vulnerability was used to escalate privileges and maintain persistence.
- Both vulnerabilities had been recently patched prior to the attack, suggesting rapid exploitation of newly disclosed flaws.
- UTA0560 leveraged these flaws to deploy GRIMWEDGE, a lightweight JavaScript backdoor.
GRIMWEDGE Backdoor Capabilities
- GRIMWEDGE functions as a stealthy backdoor written in JavaScript for cross-platform compatibility.
- It enables remote command execution, data exfiltration, and lateral movement within compromised networks.
- The backdoor communicates with attacker-controlled infrastructure using encrypted channels.
- Its design avoids detection by traditional signature-based security tools.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.