INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Volexity Exploits Chrome Zero-Day in GRIMWEDGE Attack

| 2026-09-22 18:47 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat group UTA0565, linked to China-aligned activities and exploiting vulnerabilities in Chrome and Microsoft, has been spotted across multiple campaigns. This coordinated effort suggests a large-scale exploitation kit shared among multiple groups within the Chinese computer network. Researchers at Volexity have identified similar tactics used by other threat actors, including JungleBamboo (aka APT31), which deployed a loader named SUPERSTOMP to install LONGTALE, a Chrome extension known as GemStone. This near-simultaneous use of the same exploit chain in China raises concerns that it may have been sold or made available to them by the exploit developer after possibly reverse-engineering the changes in the Chromium source code.
Technical Mitigations AI-generated
* Use up-to-date and patched versions of Google Chrome and Microsoft Windows to prevent exploitation of the CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 zero-day vulnerabilities. * Implement a web application firewall (WAF) or content security policy (CSP) to block malicious JavaScript code from being executed on websites that may be targeted by UTA0565. * Regularly scan for and remove malware, including the "CLEANGULP" malware family tracked by Volexity, which is known to be used in various threat groups, including those attributed to GRIMWEDGE. * Use a secure email client or service with built-in phishing protection to prevent UTA0565 from sending phishing emails that target multiple non-governmental organizations (NGOs) and other entities. * Monitor for suspicious activity on websites targeted by UTA0565 and take prompt action if necessary, such as blocking access to the website or reporting it to the relevant authorities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

oc•••••.top
ms•••••.exe
ws•••••.dll
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-87491CVE-2026-87491 CVE-2026-85046CVE-2026-85046 CVE-2026-85880CVE-2026-85880
Target & Sectors
HK CN
mediamedia governmentgovernment
Incident Timeline
‎between Sept. 3 and 4
The China-aligned threat group UTA0565 exploited vulnerabilities in Chrome and Microsoft between September 3 and 4.
organisation UTA0565
organisation Chrome
‎September 1, 2026
Threat actors exploited vulnerabilities in Chrome and Microsoft to target non-governmental organizations on September 1, 2026.
‎Sept. 8
Threat actors exploited remote-code execution defects in the JavaScript engine for Chromium-based browsers to target Windows systems.
vulnerability CVE-2026-85046
vulnerability CVE-2026-87491
vulnerability CVE-2026-85880
infrastructure Windows
tactic T1059.007 - JavaScript
organisation Chromium
organisation Windows Advanced Local Procedure Call
‎2026/09/08
Threat actors exploited a known vulnerability in Chrome and Microsoft's security updates to target China-aligned groups before official patches were released.
organisation Google
‎2026/09/22
Chinese threat actors exploited recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.
organisation Microsoft
organisation the Center for American Progress
organisation China Digital Times
infrastructure Windows
organisation Google Chrome
organisation Microsoft Windows
organisation JungleBamboo
organisation SUPERSTOMP
organisation LONGTALE
organisation GemStone
organisation Chrome-Windows
organisation DLL
organisation MSI
organisation Chromium
organisation Chrome
organisation GRIMWEDGE
organisation PID
organisation Upload
data_breach 5 MB Run
organisation Run and Upload
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
5
Mb Run