NewsTradingSentimentCalendarCommunityBriefing
Tech

Chinese Hackers Use Chrome and Windows Flaws to Deploy Backdoor

By Tech Desk · 2026-09-15 · 2 min read
A cracked digital shield against a dark background
Illustration: Tradingbird

A sophisticated phishing campaign has exploited patched security flaws in common software to install a stealthy JavaScript backdoor on non-governmental organizations.

Researchers have identified a sophisticated spear-phishing campaign attributed to a Chinese state-linked threat actor. The operation targeted multiple non-governmental organizations on September 1, 2026, exploiting recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor known as GRIMWEDGE. According to The Hacker News, the activity was tracked by cybersecurity firm Volexity under the designation UTA0560.

The attack began with deceptive emails containing links that appeared to lead to a legitimate U.S. university website. In reality, these links abused a reflected cross-site scripting vulnerability to redirect recipients to infrastructure controlled by the attackers. This initial step triggered a complex exploit chain that ultimately installed the backdoor, providing the threat actor with a persistent foothold on the compromised systems.

Exploit Chain Targets Browser and OS

The campaign relied on a three-step exploit chain involving two flaws in Chrome and one in Windows. The first flaw allowed arbitrary read and write access within the browser’s internal sandbox. The second flaw enabled the attacker to escape this sandbox entirely. The third flaw facilitated code injection into the browser process, achieving arbitrary code execution on the host system.

The attackers specifically targeted systems running Chrome on Windows, filtering out other configurations to ensure the exploit chain would work. The final stage of the exploit embedded three binary payloads as encoded strings within JavaScript. These payloads were designed to perform host reconnaissance, escalate privileges within the Windows kernel, and inject code into the browser process to download additional malware.

Backdoor Offers Limited but Persistent Control

Once installed, the GRIMWEDGE backdoor operates through a command-and-control server, polling it for instructions that are executed in memory. The tool provides capabilities for system reconnaissance, directory management, file deletion, and process termination. It can also read files up to 5 MB and execute commands in hidden windows.

However, the backdoor lacks built-in mechanisms for lateral movement or data exfiltration beyond basic file reading. Researchers noted that it serves primarily as an initial foothold, allowing the threat actor to survey the host, retrieve specific files, and deploy additional tooling. This limited functionality suggests the backdoor is part of a larger, multi-stage intrusion rather than a standalone attack.

Second Actor Uses Same Exploit Chain

Volexity also observed a second China-nexus threat actor, known as JungleBamboo or APT31, using the same exploit chain around the same time. This group deployed a different loader named SUPERSTOMP, which subsequently installed a payload known as LONGTALE. The concurrent use of the same zero-day vulnerabilities by distinct actors highlights the high value placed on these flaws in the underground cybercrime market.

The trade-off for organizations facing such threats is the need for immediate patching and strict email security measures. Since the attack relies on user interaction and specific software versions, keeping browsers and operating systems up to date remains the primary defense. The incident underscores that even patched flaws can be exploited if users are tricked into visiting malicious links.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories