China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

September 15, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Non-governmental organizations (NGOs)
Incident: A spear-phishing campaign exploiting a zero-day chain to deliver the GRIMWEDGE backdoor.
Impact: Full system compromise allowing for remote host reconnaissance, file management, and arbitrary command execution.
Attacker: UTA0560 (China-linked)
Analysis: The threat group UTA0560 is utilizing a multi-stage exploit chain known as BlueMoon to achieve arbitrary code execution on Windows systems. By chaining vulnerabilities in Google Chrome’s V8 engine and Windows ALPC, the actors can bypass the browser sandbox and escalate privileges. This process culminates in the deployment of GRIMWEDGE, a JavaScript-based backdoor used for reconnaissance and remote command execution.
Recommendations: Immediately update Google Chrome and Microsoft Windows to the latest patched versions.; Implement robust email security filters to detect and block spear-phishing attempts and malicious redirects.; Monitor network logs for traffic to the known C2 domain ocr.opusaccel[.]top.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *