HomeCyber BalkansChina-Linked Hackers Link Chrome Zero-Day to Windows Kernel Vulnerability in Attacks

China-Linked Hackers Link Chrome Zero-Day to Windows Kernel Vulnerability in Attacks

Published on

spot_img

China-Linked Hackers Exploit Browser and Kernel Vulnerabilities to Target NGOs

In a sophisticated cyber operation, threat actors associated with China, identified as UTA0560 and JungleBamboo, have successfully executed a double exploitation of vulnerabilities in Google Chrome and the Windows kernel. This advanced attack, primarily aimed at non-governmental organizations (NGOs) and other victims, was documented by Volexity and detected on September 1, 2026. These operations utilized a combination of a JavaScript engine flaw and a Windows kernel privilege-escalation defect, leveraging them in targeted phishing campaigns designed to infiltrate sensitive organizations.

Volexity’s findings highlight the attackers’ intricate methodology, wherein they deployed identical exploit components for both the browser and the kernel while ultimately installing distinct espionage payloads. One payload, known as GRIMWEDGE, functions as a JScript backdoor, while the other, dubbed LONGTALE, is a credential-stealing Chrome extension. The initial phase of the intrusion began with spear-phishing emails containing links to seemingly legitimate U.S. university websites. These sites were exploited for reflected cross-site scripting vulnerabilities, allowing the threat actors to redirect targets to malicious landing pages.

The method employed by UTA0560 and JungleBamboo involved presenting victims with convincing images of donation forms, while hidden scripts executed the malicious exploit chain. At the core of this operation was CVE-2026-85046, a type-confusion issue within the V8 JavaScript engine. While a patch had been introduced to Chromium’s open-source code following private reporting in August, Chrome had not yet officially shipped the fix, leaving users vulnerable. This gap in protection effectively rendered the vulnerability a zero-day against unsuspecting Chrome users.

The exploit allowed attackers to achieve arbitrary read and write access within the V8 sandbox. Subsequently, they exploited an additional vulnerability, identified as CVE-2026-87491—a defect in WebAssembly—to escape the sandbox environment. A third identified flaw, CVE-2026-85880, found within the Windows kernel component RtlpCreateServerAcl, rendered the attackers with the necessary privileges to break free from Chrome’s sandboxed renderer. Ultimately, this sequence culminated in executing shellcode that integrated itself into Chrome’s browser process, downloading a selected payload through an exeurl parameter.

Constructed with an emphasis on both reliability and stealth, the exploit utilized a Web Worker to ensure that if an exploit attempt crashed, the browser tab would remain visible. It also included a mechanism for retrying recoverable failures up to five times. The reconnaissance phase of this attack was thorough; it involved gathering detailed information regarding the targeted system, such as Windows version, token privileges, CPU specifications, and hypervisor indicators, before executing the kernel exploit against the chosen Windows builds.

During the exploitation, UTA0560 utilized financial-themed NGO lures to facilitate the download of GRIMWEDGE through an elaborate installation chain. This involved a dropper that extracted a legitimate executable and sideloaded a Dynamic Link Library (DLL), establishing a scheduled task named “Windows Scheduled System” to facilitate data gathering and execution of subsequent payloads.

Interestingly, JungleBamboo, which is also known by various aliases including APT31, Violet Typhoon, and TA412, employed distinct infrastructure while utilizing byte-for-byte identical exploitation shellcode. The group leveraged the SUPERSTOMP loader to tamper with Chrome’s secure preferences, allowing the deployment of LONGTALE, which masqueraded as a Google Gemini extension. This extension is capable of capturing keystrokes, form data, cookies, session storage, screenshots, and browsing histories, in addition to supporting remote command execution.

Volexity assessed with medium confidence that the shared exploit developer may have provided or sold this exploit chain to various Chinese operators. They likely capitalized on the vulnerability window created by Chrome’s delayed release of security patches. This highlights a critical cybersecurity lesson—the time between patch disclosure and actual software updates can provide adversaries with invaluable time to exploit these vulnerabilities.

To mitigate risks and defend against such sophisticated cyber threats, organizations are urged to update Chrome and Windows immediately upon release of security patches. Furthermore, they should investigate any phishing redirects and unexpected browser behaviors carefully. Security analysts and defenders should also remain vigilant for any suspicious scheduled tasks, changes to extensions, and outbound connections to known malicious infrastructure.

As a part of the ongoing efforts to bolster cybersecurity, maintaining up-to-date awareness of active malware and phishing threats is critical. Initiatives encouraging early detection and preventative measures can significantly reduce the likelihood of successful cyber intrusions. Organizations are encouraged to utilize comprehensive cybersecurity solutions that offer real-time updates on potential threats, ensuring they remain one step ahead in the ever-evolving landscape of cyber warfare. This case serves as a potent reminder of the dynamic nature of cyber threats and reinforces the necessity of robust cybersecurity measures and proactive defense strategies.

Source link

Latest articles

Wipro and CrowdStrike Introduce CISO Command Center

Wipro and CrowdStrike Collaborate to Establish CISO Command Center Amid IT Sector Transformations Wipro, a...

Threat Actors Leverage Claude AI Agents to Automate Cyberattacks and Exfiltrate Sensitive Data

Recent developments indicate that threat actors are increasingly leveraging Claude-based AI workflows to enhance...

Who Controls the AI Acting on Your Behalf? Exploring the Identity Problem in Autonomous AI Webinar

ISMG Registration: A Step Towards Enhanced Professional Networking In a significant move to foster professional...

Forescout Expands Global Investment in Channel Partners

Forescout Amplifies Global Partner Investment to Enhance Cybersecurity Ecosystem Forescout Technologies, a leader in cybersecurity,...

More like this

Wipro and CrowdStrike Introduce CISO Command Center

Wipro and CrowdStrike Collaborate to Establish CISO Command Center Amid IT Sector Transformations Wipro, a...

Threat Actors Leverage Claude AI Agents to Automate Cyberattacks and Exfiltrate Sensitive Data

Recent developments indicate that threat actors are increasingly leveraging Claude-based AI workflows to enhance...

Who Controls the AI Acting on Your Behalf? Exploring the Identity Problem in Autonomous AI Webinar

ISMG Registration: A Step Towards Enhanced Professional Networking In a significant move to foster professional...