China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

Summary

A Chinese threat actor, tracked as UTA0560 by Volexity, conducted a spear-phishing campaign targeting NGOs on September 1, 2026. This campaign exploited a chain of zero-day vulnerabilities in Google Chrome and Microsoft Windows to deploy a malicious JavaScript backdoor named GRIMWEDGE.

IFF Assessment

FOE

The discovery of a zero-day exploit chain used by a nation-state-linked actor to deploy malware represents a significant threat to organizations.

Severity

9.0 Critical (AI Estimated)

Exploiting a chain of zero-day vulnerabilities in both a popular browser (Chrome) and a major operating system (Windows) likely allows for remote code execution with high privileges, leading to a critical impact on confidentiality, integrity, and availability.

Defender Context

This incident highlights the ongoing threat of sophisticated spear-phishing attacks utilizing chained zero-day exploits against critical software. Defenders should remain vigilant for indicators of compromise related to GRIMWEDGE and ensure timely patching of all software, especially browsers and operating systems, while also reinforcing user education on phishing attempts.

Read Full Story →