Volexity Details Chinese Actors’ Chrome–Windows Exploit Chain Used in Two Espionage Campaigns

Summary
Volexity reports that UTA0560 and JungleBamboo used the same Chrome–Windows exploit chain in phishing campaigns, despite a gap between Chromium fixes and Chrome releases, to deploy distinct backdoors and credential-stealing malware.
Key points
- Volexity observed UTA0560 and JungleBamboo targeting separate groups of NGO-related targets in phishing campaigns beginning September 1, 2026.
- Phishing links abused reflected XSS on a legitimate university website or actor-controlled infrastructure to deliver an exploit chain targeting Chrome on Windows.
- The chain used Chrome V8 type confusion CVE-2026-85046, a WebAssembly flaw CVE-2026-87491, and Windows kernel privilege-escalation vulnerability CVE-2026-85880 to escape browser sandboxes and execute payloads.
- The Chrome flaw had been fixed in Chromium source but the fix had not yet reached a Chrome release during the observed campaigns, creating a patch gap.
- UTA0560 deployed GRIMWEDGE, a JScript backdoor supporting reconnaissance, file operations, command execution, and file transfer; it also established persistence through a scheduled task.
- JungleBamboo used SUPERSTOMP to install the LONGTALE Chrome extension, which captures keystrokes and form data, steals cookies and session tokens, and sends collected information to its operators.
- Volexity assesses that the shared exploit chain may have been provided to separate operators; it reports that Microsoft assisted in investigating and remediating the Windows kernel vulnerability.
Article Details
- Attack Vectors
- UTA0560 sent spear-phishing emails to NGO targets. A link abused reflected XSS on a legitimate university website to redirect recipients to an attacker-hosted Chrome exploit.
- JungleBamboo sent phishing links to its own infrastructure, which hosted the same exploit chain but delivered different malware.
- The shared chain combined CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escape browser sandboxes, inject into the Chrome browser process, and execute a downloaded payload.
- UTA0560 used a DLL-sideloading loader and a scheduled task to deliver GRIMWEDGE. JungleBamboo used SUPERSTOMP to install the credential-stealing LONGTALE Chrome extension.
- Defensive Notes
- Volexity reported that fixes present in Chromium source had not reached a released Google Chrome version when the phishing occurred.
- The exploit loader proceeded only for Chrome running on Windows.
- SUPERSTOMP removed encrypted integrity values from Chrome Secure Preferences and supplied forged legacy HMAC values. Volexity reported that released Chrome versions still permitted the legacy fallback as of 2026-09-08.
- UTA0560's loader created a scheduled task named “Windows Scheduled System” to rerun its sideloading chain every five minutes.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | gitprogram[.]com | JungleBamboo phishing and C2 infrastructure. |
| DOMAIN | msbenefit[.]com | JungleBamboo phishing infrastructure. |
| DOMAIN | ocr[.]opusaccel[.]top | UTA0560 GRIMWEDGE backdoor C2 domain. |
| HOSTNAME | cloud[.]shinewrist[.]net | UTA0560 C2 and exploit-hosting infrastructure. |
| HOSTNAME | d71bedcf-307a-4432-beec-ce943223d0e3[.]cfargotunnel[.]com | Cloudflare Tunnel hostname shown as the DNS canonical name for JungleBamboo infrastructure. |
| HOSTNAME | document[.]gitprogram[.]com | JungleBamboo infrastructure whose DNS response Volexity cited as indicating Cloudflare Tunnel use. |
| HOSTNAME | photos[.]msbenefit[.]com | Host used in JungleBamboo phishing links. |
| HOSTNAME | proof[.]gitprogram[.]com | JungleBamboo host that served the shared exploit chain. |
| HOSTNAME | xyz0102[.]gitprogram[.]com | JungleBamboo host used to deliver the LONGTALE extension. |
| IPV4 | 206[.]166[.]251[.]164 | IP hosting UTA0560's exploit and C2 host; Volexity linked it to earlier staging activity. |
| SHA256 | 337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d | UTA0560 react.min.js malicious JavaScript loader. |
| SHA256 | 3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f | UTA0560 sideloaded wsc.dll loader. |
| SHA256 | 51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863cc | Shared p2 Windows kernel exploit DLL. |
| SHA256 | 56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951 | UTA0560 Temp.txt MSI payload in the GRIMWEDGE chain. |
| SHA256 | 5995f42a828606705a7339d58a665c229936e81c4e539cdfa115eb46a2eb53d6 | Shared p2 binary exploit data. |
| SHA256 | 59dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcb | UTA0560 GRIMWEDGE JScript backdoor. |
| SHA256 | 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3 | JungleBamboo a001 LONGTALE Chrome extension. |
| SHA256 | 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc | UTA0560 msgbox.exe dropper in the GRIMWEDGE chain. |
| SHA256 | 7a52ff23949edee8faa61ce0def6dbca8b7e5943c54d23376cc190762ea3985c | Shared page.html exploit component. |
| SHA256 | b7b0cd6539464ab39c6526e499f86d611faa21c5af945535ebaf187cec543af1 | Shared p1 reconnaissance DLL. |
| SHA256 | cd0c21f9b32b7feeda1787fccab622dec60ecdf84c0538c08bde3946856b0fa0 | Shared p1 binary exploit data. |
| SHA256 | d17053557bb90298f7b115432b4820a248fdbe678bca31721529b1f51a82343b | UTA0560 Files1.html exploit landing page. |
| SHA256 | e2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c0 | JungleBamboo msgbox.exe SUPERSTOMP loader. |
| URL | hxxps[:]//cloud[.]shinewrist[.]net/<removed>/%COMPUTERNAME%[.]txt | UTA0560 loader's victim-specific C2 staging URL pattern. |
| URL | hxxps[:]//cloud[.]shinewrist[.]net/<removed>/Files1[.]html | UTA0560 exploit landing page reached after the phishing redirect. |
| URL | hxxps[:]//cloud[.]shinewrist[.]net/<removed>/msgbox[.]exe | UTA0560 payload download URL used after browser-process injection. |
| URL | hxxps[:]//cloud[.]shinewrist[.]net/<removed>/page[.]html?mode=payload | Configured URL for UTA0560's exploit delivery page. |
| URL | hxxps[:]//cloud[.]shinewrist[.]net/<removed>/page[.]html?mode=payload&exeurl=hxxp://cloud[.]shinewrist[.]net/<removed>/msgbox[.]exe | Exploit URL assembled by UTA0560's loader, including its payload location. |
| URL | hxxps[:]//cloud[.]shinewrist[.]net/<removed>/react[.]min[.]js | UTA0560-hosted malicious JavaScript exploit loader. |
| URL | hxxps[:]//ocr[.]opusaccel[.]top | GRIMWEDGE JScript backdoor C2 endpoint. |
| URL | hxxps[:]//photos[.]msbenefit[.]com/fa/t3 | JungleBamboo September 1 phishing URL listed in the network indicators. |
| URL | hxxps[:]//photos[.]msbenefit[.]com/fb/w3z | Link in a JungleBamboo phishing email; Volexity said it was unavailable during analysis. |
| URL | hxxps[:]//proof[.]gitprogram[.]com/a4/j8 | JungleBamboo phishing URL that hosted the shared Chrome exploit chain. |
| URL | hxxps[:]//xyz0102[.]gitprogram[.]com/a001 | JungleBamboo URL from which SUPERSTOMP downloaded the LONGTALE extension. |
MITRE ATT&CK
T1041 · Exfiltration Over C2 ChannelLONGTALE periodically sent collected browser data, including keystrokes, cookies, and navigation history, to its C2.T1053.005 · Scheduled TaskUTA0560's wsc.dll created the “Windows Scheduled System” task to rerun the sideloading chain every five minutes.T1055 · Process InjectionThe pp payload injected code into the Chrome browser process after privilege escalation.T1056.001 · KeyloggingLONGTALE recorded keystrokes and input-field values across browser tabs.T1059.007 · JavaScriptThe GRIMWEDGE MSI executed obfuscated JScript and evaluated JScript returned by its C2.T1068 · Exploitation for Privilege EscalationThe p2 payload exploited CVE-2026-85880 in the Windows kernel to elevate privileges and escape Chrome's renderer sandbox.T1071.001 · Web ProtocolsGRIMWEDGE used HTTP POST requests to send host details and command output to its C2 and receive JScript responses.T1105 · Ingress Tool TransferThe injected code downloaded and executed a next-stage payload; UTA0560's loader also retrieved a per-host MSI payload.T1113 · Screen CaptureLONGTALE captured JPEG screenshots when page content matched C2-supplied keywords.T1176.001 · Browser ExtensionsSUPERSTOMP altered Chrome Secure Preferences to install and enable the malicious LONGTALE browser extension.T1203 · Exploitation for Client ExecutionThe phishing links led to a page exploiting Chrome V8 and WebAssembly vulnerabilities in the browser.T1539 · Steal Web Session CookieLONGTALE stole browser cookies and session-storage tokens.T1566.002 · Spearphishing LinkBoth actors sent phishing emails containing links that led targets toward their exploit infrastructure.T1574.002 · DLL Side-LoadingUTA0560's dropper extracted a legitimate executable and a malicious wsc.dll that was loaded through DLL sideloading.
CVE
CVE-2026-85046infrastructure hosting a multi-stage exploit chain that included a Google Chrome zero-day, CVE-2026-85046.CVE-2026-85880It then exploits a third vulnerability in the Windows kernel (CVE-2026-85880) to escape Chrome’s sandboxed renderer process and inject code into the Chrome browser process.CVE-2026-87491The exploit first gains arbitrary read/write within the V8 sandbox through the Type confusion vulnerability (CVE-2026-85046), then combines a separate WebAssembly defect to escape the V8 sandbox (CVE-2026-87491).
Threat Actors
Malware
GRIMWEDGEUTA0560 downloaded and deployed the GRIMWEDGE JScript backdoor providing host reconnaissance, file and process management, command execution, and payload delivery capabilities.LONGTALEJungleBamboo deployed SUPERSTOMP, a loader that installed the LONGTALE credential-stealing Chrome extension.SUPERSTOMPJungleBamboo deployed SUPERSTOMP, a loader that installed the LONGTALE credential-stealing Chrome extension.
Vendors
Products
ChromiumCVE-2026-85046 was reported to the Chromium project by a private security researcher on August 4, 2026.Google Chrometo threat-actor-controlled infrastructure hosting a multi-stage exploit chain that included a Google Chrome zero-day, CVE-2026-85046.Microsoft WindowsIt then exploits a third vulnerability in the Windows kernel (CVE-2026-85880) to escape Chrome’s sandboxed renderer process and inject code into the Chrome browser process.