China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy New Backdoor
Security researchers at Volexity have identified a spear-phishing campaign, tracked as UTA0560, that targeted non-governmental organisations in September 2026 using a sophisticated exploit chain. Victims received emails urging them to click a link to what appeared to be a legitimate US university website. That site contained a cross-site scripting flaw the attackers abused to redirect visitors to malicious infrastructure hosting a three-stage exploit chain affecting Google Chrome and Microsoft Windows.
The exploit chain used three vulnerabilities, since patched, to gain full control of a victim's browser and ultimately execute code on their computer. The attackers only triggered the exploit for visitors using Chrome on Windows, filtering out other systems. Once successful, the attack delivered a loader that installed a malicious file alongside a legitimate Windows program to sneak past security tools, ultimately deploying the GRIMWEDGE backdoor. This malware can explore infected systems, manage files and processes, run commands, and download further malicious tools.
While this campaign has so far focused on NGOs, the use of a compromised legitimate website and now-patched software flaws highlights how attackers combine social engineering with technical exploits to bypass defences.