Threat Intelligence

China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy New Backdoor

The Hacker News · 15 Sept 2026
Key Takeaway Ensure Chrome and Windows are fully updated with the latest security patches, and train staff to be cautious of unexpected email links even when they appear to point to trusted websites.

Security researchers at Volexity have identified a spear-phishing campaign, tracked as UTA0560, that targeted non-governmental organisations in September 2026 using a sophisticated exploit chain. Victims received emails urging them to click a link to what appeared to be a legitimate US university website. That site contained a cross-site scripting flaw the attackers abused to redirect visitors to malicious infrastructure hosting a three-stage exploit chain affecting Google Chrome and Microsoft Windows.

The exploit chain used three vulnerabilities, since patched, to gain full control of a victim's browser and ultimately execute code on their computer. The attackers only triggered the exploit for visitors using Chrome on Windows, filtering out other systems. Once successful, the attack delivered a loader that installed a malicious file alongside a legitimate Windows program to sneak past security tools, ultimately deploying the GRIMWEDGE backdoor. This malware can explore infected systems, manage files and processes, run commands, and download further malicious tools.

While this campaign has so far focused on NGOs, the use of a compromised legitimate website and now-patched software flaws highlights how attackers combine social engineering with technical exploits to bypass defences.

zero-day phishing backdoor Chrome vulnerability China-linked threat actor

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.