Volexity Details Chinese Actors’ Chrome–Windows Exploit Chain Used in Two Espionage Campaigns

· Original article ↗

Summary

Volexity reports that UTA0560 and JungleBamboo used the same Chrome–Windows exploit chain in phishing campaigns, despite a gap between Chromium fixes and Chrome releases, to deploy distinct backdoors and credential-stealing malware.

Key points

  • Volexity observed UTA0560 and JungleBamboo targeting separate groups of NGO-related targets in phishing campaigns beginning September 1, 2026.
  • Phishing links abused reflected XSS on a legitimate university website or actor-controlled infrastructure to deliver an exploit chain targeting Chrome on Windows.
  • The chain used Chrome V8 type confusion CVE-2026-85046, a WebAssembly flaw CVE-2026-87491, and Windows kernel privilege-escalation vulnerability CVE-2026-85880 to escape browser sandboxes and execute payloads.
  • The Chrome flaw had been fixed in Chromium source but the fix had not yet reached a Chrome release during the observed campaigns, creating a patch gap.
  • UTA0560 deployed GRIMWEDGE, a JScript backdoor supporting reconnaissance, file operations, command execution, and file transfer; it also established persistence through a scheduled task.
  • JungleBamboo used SUPERSTOMP to install the LONGTALE Chrome extension, which captures keystrokes and form data, steals cookies and session tokens, and sends collected information to its operators.
  • Volexity assesses that the shared exploit chain may have been provided to separate operators; it reports that Microsoft assisted in investigating and remediating the Windows kernel vulnerability.

Article Details

Attack Vectors
  • UTA0560 sent spear-phishing emails to NGO targets. A link abused reflected XSS on a legitimate university website to redirect recipients to an attacker-hosted Chrome exploit.
  • JungleBamboo sent phishing links to its own infrastructure, which hosted the same exploit chain but delivered different malware.
  • The shared chain combined CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escape browser sandboxes, inject into the Chrome browser process, and execute a downloaded payload.
  • UTA0560 used a DLL-sideloading loader and a scheduled task to deliver GRIMWEDGE. JungleBamboo used SUPERSTOMP to install the credential-stealing LONGTALE Chrome extension.
Defensive Notes
  • Volexity reported that fixes present in Chromium source had not reached a released Google Chrome version when the phishing occurred.
  • The exploit loader proceeded only for Chrome running on Windows.
  • SUPERSTOMP removed encrypted integrity values from Chrome Secure Preferences and supplied forged legacy HMAC values. Volexity reported that released Chrome versions still permitted the legacy fallback as of 2026-09-08.
  • UTA0560's loader created a scheduled task named “Windows Scheduled System” to rerun its sideloading chain every five minutes.

Indicators of compromise

TypeIndicatorContext
DOMAINgitprogram[.]comJungleBamboo phishing and C2 infrastructure.
DOMAINmsbenefit[.]comJungleBamboo phishing infrastructure.
DOMAINocr[.]opusaccel[.]topUTA0560 GRIMWEDGE backdoor C2 domain.
HOSTNAMEcloud[.]shinewrist[.]netUTA0560 C2 and exploit-hosting infrastructure.
HOSTNAMEd71bedcf-307a-4432-beec-ce943223d0e3[.]cfargotunnel[.]comCloudflare Tunnel hostname shown as the DNS canonical name for JungleBamboo infrastructure.
HOSTNAMEdocument[.]gitprogram[.]comJungleBamboo infrastructure whose DNS response Volexity cited as indicating Cloudflare Tunnel use.
HOSTNAMEphotos[.]msbenefit[.]comHost used in JungleBamboo phishing links.
HOSTNAMEproof[.]gitprogram[.]comJungleBamboo host that served the shared exploit chain.
HOSTNAMExyz0102[.]gitprogram[.]comJungleBamboo host used to deliver the LONGTALE extension.
IPV4206[.]166[.]251[.]164IP hosting UTA0560's exploit and C2 host; Volexity linked it to earlier staging activity.
SHA256337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130dUTA0560 react.min.js malicious JavaScript loader.
SHA2563b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367fUTA0560 sideloaded wsc.dll loader.
SHA25651462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863ccShared p2 Windows kernel exploit DLL.
SHA25656eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951UTA0560 Temp.txt MSI payload in the GRIMWEDGE chain.
SHA2565995f42a828606705a7339d58a665c229936e81c4e539cdfa115eb46a2eb53d6Shared p2 binary exploit data.
SHA25659dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcbUTA0560 GRIMWEDGE JScript backdoor.
SHA2565eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3JungleBamboo a001 LONGTALE Chrome extension.
SHA25669c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dcUTA0560 msgbox.exe dropper in the GRIMWEDGE chain.
SHA2567a52ff23949edee8faa61ce0def6dbca8b7e5943c54d23376cc190762ea3985cShared page.html exploit component.
SHA256b7b0cd6539464ab39c6526e499f86d611faa21c5af945535ebaf187cec543af1Shared p1 reconnaissance DLL.
SHA256cd0c21f9b32b7feeda1787fccab622dec60ecdf84c0538c08bde3946856b0fa0Shared p1 binary exploit data.
SHA256d17053557bb90298f7b115432b4820a248fdbe678bca31721529b1f51a82343bUTA0560 Files1.html exploit landing page.
SHA256e2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c0JungleBamboo msgbox.exe SUPERSTOMP loader.
URLhxxps[:]//cloud[.]shinewrist[.]net/<removed>/%COMPUTERNAME%[.]txtUTA0560 loader's victim-specific C2 staging URL pattern.
URLhxxps[:]//cloud[.]shinewrist[.]net/<removed>/Files1[.]htmlUTA0560 exploit landing page reached after the phishing redirect.
URLhxxps[:]//cloud[.]shinewrist[.]net/<removed>/msgbox[.]exeUTA0560 payload download URL used after browser-process injection.
URLhxxps[:]//cloud[.]shinewrist[.]net/<removed>/page[.]html?mode=payloadConfigured URL for UTA0560's exploit delivery page.
URLhxxps[:]//cloud[.]shinewrist[.]net/<removed>/page[.]html?mode=payload&exeurl=hxxp://cloud[.]shinewrist[.]net/<removed>/msgbox[.]exeExploit URL assembled by UTA0560's loader, including its payload location.
URLhxxps[:]//cloud[.]shinewrist[.]net/<removed>/react[.]min[.]jsUTA0560-hosted malicious JavaScript exploit loader.
URLhxxps[:]//ocr[.]opusaccel[.]topGRIMWEDGE JScript backdoor C2 endpoint.
URLhxxps[:]//photos[.]msbenefit[.]com/fa/t3JungleBamboo September 1 phishing URL listed in the network indicators.
URLhxxps[:]//photos[.]msbenefit[.]com/fb/w3zLink in a JungleBamboo phishing email; Volexity said it was unavailable during analysis.
URLhxxps[:]//proof[.]gitprogram[.]com/a4/j8JungleBamboo phishing URL that hosted the shared Chrome exploit chain.
URLhxxps[:]//xyz0102[.]gitprogram[.]com/a001JungleBamboo URL from which SUPERSTOMP downloaded the LONGTALE extension.

MITRE ATT&CK

T1041 · Exfiltration Over C2 ChannelLONGTALE periodically sent collected browser data, including keystrokes, cookies, and navigation history, to its C2.T1053.005 · Scheduled TaskUTA0560's wsc.dll created the “Windows Scheduled System” task to rerun the sideloading chain every five minutes.T1055 · Process InjectionThe pp payload injected code into the Chrome browser process after privilege escalation.T1056.001 · KeyloggingLONGTALE recorded keystrokes and input-field values across browser tabs.T1059.007 · JavaScriptThe GRIMWEDGE MSI executed obfuscated JScript and evaluated JScript returned by its C2.T1068 · Exploitation for Privilege EscalationThe p2 payload exploited CVE-2026-85880 in the Windows kernel to elevate privileges and escape Chrome's renderer sandbox.T1071.001 · Web ProtocolsGRIMWEDGE used HTTP POST requests to send host details and command output to its C2 and receive JScript responses.T1105 · Ingress Tool TransferThe injected code downloaded and executed a next-stage payload; UTA0560's loader also retrieved a per-host MSI payload.T1113 · Screen CaptureLONGTALE captured JPEG screenshots when page content matched C2-supplied keywords.T1176.001 · Browser ExtensionsSUPERSTOMP altered Chrome Secure Preferences to install and enable the malicious LONGTALE browser extension.T1203 · Exploitation for Client ExecutionThe phishing links led to a page exploiting Chrome V8 and WebAssembly vulnerabilities in the browser.T1539 · Steal Web Session CookieLONGTALE stole browser cookies and session-storage tokens.T1566.002 · Spearphishing LinkBoth actors sent phishing emails containing links that led targets toward their exploit infrastructure.T1574.002 · DLL Side-LoadingUTA0560's dropper extracted a legitimate executable and a malicious wsc.dll that was loaded through DLL sideloading.

CVE

Threat Actors

Malware

Vendors

Products

Countries

Industries

Related Articles