A spear-phishing campaign is using a recently patched Chrome and Windows exploit chain to plant backdoors on NGO networks, according to Volexity.
The emails sent on September 1 pushed recipients toward a US university website. A reflected cross-site scripting flaw there redirected visitors to attacker infrastructure hosting the exploit chain, which only fired for Chrome on Windows.
That chain, earlier documented by Proofpoint as BlueMoon, links three bugs. CVE-2026-85046 gives read and write access inside the V8 sandbox, CVE-2026-87491 breaks out of the browser sandbox, and CVE-2026-85880, a heap overflow in Windows ALPC, finishes with code execution.
Volexity tied one cluster, UTA0560, to a JavaScript backdoor called GRIMWEDGE. Delivered through a loader named msgbox.exe, it polls a command server and runs instructions in memory, supporting host reconnaissance, file and process management, command execution, and uploads. It carries no persistence or lateral movement of its own.
A second China-linked group, JungleBamboo, used the same chain to install SUPERSTOMP and a credential-stealing Chrome extension called LONGTALE. The extension disguises itself as Google Gemini, logging keystrokes, lifting cookies and sessions, and taking screenshots when pages match keywords.
The overlap between the crews suggests the exploit chain may have been shared or sold. It also highlights a patch gap: fixes had landed in Chromium but not yet in a stable Chrome release, so two N-days worked as zero-days.
