Chrome and Windows Exploit Chain | Image: Volexity
At a glance
| Field | Details |
|---|---|
| Actor or Group | Suspected Chinese espionage groups UTA0560 and JungleBamboo (APT31) |
| Activity Type | Spear-phishing, browser zero-day exploitation, credential theft, and malware delivery |
| Targets or Victims | Non-governmental organizations (NGOs) and public policy research institutes |
| Scale | Targeted intrusions impacting multiple enterprise networks across international borders |
| Jurisdiction Status | Tracked by private security researchers; US authorities previously indicted APT31 actors |
| Source | Volexity Network Security Monitoring |
Executive Summary
Security researchers identified multiple Chinese espionage groups exploiting an unpatched browser vulnerability. The attackers weaponized an upstream Chromium fix before Google rolled the update into stable desktop builds. Consequently, enterprise security teams must update Google Chrome immediately and audit endpoints for unauthorized persistence mechanisms.
What Happened in the Chrome Exploitation Wave
Volexity detected the malicious activity through its network security monitoring platform on September 1, 2026. The report confirms, “Volexity’s Network Security Monitoring (NSM) service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmental organizations.”
The attackers sent deceptive emails offering financial donations to policy research groups. Furthermore, the messages included links to an American university website. The hackers exploited a reflected cross-site scripting flaw on the educational portal to redirect visitors to attacker-controlled infrastructure.
Once redirected, the victim landed on an exploit page displaying a fake donation form. Meanwhile, background scripts assembled the exploit inside a hidden iframe. The operation targeted a type-confusion flaw in the V8 engine tracked as CVE-2026-85046.
A private security researcher reported this bug on August 4, 2026. Developers committed a fix to the Chromium open-source repository soon after. However, the fix had not reached stable releases of Google Chrome when the attacks started.
The report highlights this dangerous window. The report notes, “The vulnerability was known and fixed upstream, making it an N-day at the Chromium source level, but there was no patch release for Google Chrome users.”
The full attack sequence chained multiple weaknesses together. First, the Chrome zero-day exploit chain achieved memory read and write access inside the V8 engine. Next, the script exploited a WebAssembly defect tracked as CVE-2026-87491 to escape the V8 sandbox. Finally, the chain exploited a Windows kernel vulnerability, CVE-2026-85880, to break out of the renderer sandbox and inject code into the main browser process.
Technical details in the Volexity threat intelligence report show that the code ran inside a dedicated Web Worker thread. This design prevented the browser tab from crashing during failed attempts.
Who Is Behind the Campaign
Volexity identified two distinct Chinese threat groups using the same underlying exploit code. The report states, “Volexity observed two distinct clusters of activity using the exploit chain to deliver different payloads.”
The first actor, UTA0560, targeted non-governmental organizations using financial lures. Volexity attributed this activity to UTA0560 with high confidence. The campaign reused email accounts, hosting infrastructure, and beaconing routines previously observed in March 2026.
Meanwhile, the second cluster involved JungleBamboo, also known as APT31 or Violet Typhoon. This group sent phishing emails concerning academic misconduct to separate corporate targets. The threat actors hosted the exploit on dedicated domains matching historical JungleBamboo registration habits.
Researchers assess with medium confidence that both groups obtained the exploit chain from a shared developer or central procurement hub. The short disclosure window likely forced both groups to reuse the core shellcode without modification.
Impact and Post-Exploitation Activity
Although both groups shared the exploit chain, their post-exploitation payloads differed significantly. UTA0560 deployed a multi-stage loader that sideloaded a malicious dynamic link library. This library created a scheduled task called Windows Scheduled System to secure persistence.
The loader then deployed GRIMWEDGE, a compact JScript backdoor running entirely in memory. GRIMWEDGE allows operators to survey system settings, list running processes, execute commands, and upload secondary files.
In contrast, JungleBamboo focused strictly on identity and credential theft. The group delivered a custom loader named SUPERSTOMP. The advisory explains, “SUPERSTOMP uses Secure Preferences tampering to install a malicious Chrome extension.”
The loader bypassed browser integrity checks by forging legacy cryptographic values. It then installed a rogue extension named LONGTALE disguised as Google Gemini. LONGTALE captures keystrokes across all tabs, steals session cookies, and takes keyword-triggered screenshots without executing arbitrary system commands.
What Comes Next and Defense Guidance
The open-source patch gap presents growing risks as threat actors monitor public repositories for security fixes. Organizations must implement layered defenses to mitigate these fast-moving threats.
Recommended Mitigation Steps
- Apply Google Chrome and Chromium browser updates immediately to eliminate the V8 vulnerability.
- Upgrade older Windows systems to modern builds that mitigate kernel privilege escalation.
- Monitor endpoints for unusual scheduled tasks, particularly tasks launching executables from temporary directories.
- Audit installed browser extensions across enterprise fleets to identify unauthorized software.
- Inspect network traffic for command beacons connecting to unverified top-level domains.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!