Microsoft: Chinese Hackers Chain Chrome and Windows Zero-Days to Deploy Backdoors and Steal Credentials

Microsoft: Chinese Hackers Chain Chrome and Windows Zero-Days to Deploy Backdoors and Steal Credentials

Chinese APT Groups Exploit Chrome and Windows Zero-Days in Targeted Espionage Campaign

A recently uncovered exploit chain targeting Google Chrome and the Windows kernel has been leveraged by Chinese state-linked threat groups UTA0560 (APT31/Violet Typhoon/TA412) and JungleBamboo to deploy espionage malware and steal browser credentials.

The campaign exploited CVE-2026-85046, a type-confusion flaw in Chrome’s V8 JavaScript engine, alongside CVE-2026-87491 (a WebAssembly sandbox-escape vulnerability) and CVE-2026-85880 (a Windows kernel privilege-escalation flaw in RtlpCreateServerAcl). Despite a fix being available in the Chromium codebase, the patch had not yet been rolled out to Chrome users, creating a patch-gap window that effectively turned the vulnerability into a zero-day exploit.

Victims were lured via spear-phishing emails containing links to legitimate but vulnerable websites compromised with reflected cross-site scripting (XSS). The XSS flaw redirected users to attacker-controlled infrastructure, where a hidden iframe executed the exploit while displaying a decoy donation-form image tailored to the victim’s organization.

The exploit chain began by escaping Chrome’s V8 sandbox, then leveraging the WebAssembly flaw to break out of the renderer process. The Windows kernel exploit allowed attackers to inject code into Chrome’s main process, bypassing security restrictions. The exploit included automatic retry mechanisms (up to five attempts) and host fingerprinting to assess system details such as Windows version, token privileges, and virtualization status before proceeding with privilege escalation.

While the exploit code was identical across both threat groups, their post-exploitation payloads differed:

  • UTA0560 deployed GRIMWEDGE, a JScript backdoor delivered via a DLL sideloading technique using a legitimate executable (msgbox.exe). The malware established persistence via a scheduled task named “Windows Scheduled System” and operated in memory within msiexec.exe. Capabilities included reconnaissance, file theft, process manipulation, and command execution, with C2 traffic containing victim identifiers and command outputs.

  • JungleBamboo delivered SUPERSTOMP, a tool that tampered with Chrome’s Secure Preferences to install a malicious extension (LONGTALE). By removing encrypted hashes and generating valid legacy HMAC values, the attackers bypassed extension-integrity checks. The extension, disguised as a Google Gemini add-on, enabled keylogging, form data capture, clipboard theft, cookie exfiltration, screenshot harvesting, and browsing history collection.

Volexity’s analysis suggests the exploit chain may have been shared or sold among multiple Chinese threat actors, highlighting the risks of publicly disclosed upstream fixes providing attackers a narrow window to weaponize vulnerabilities before downstream patches are deployed.

The campaign underscores the criticality of rapid patching for Chrome and Windows, as well as the need to monitor for browser extension tampering and phishing redirects through compromised legitimate sites.

Source: https://cyberpress.org/chinese-hackers-chain-chrome-and-windows-zero-days/

Microsoft Threat Intelligence cybersecurity rating report: https://www.rankiteo.com/company/microsoft-threat-intelligence

"id": "MIC1789201438",
"linkid": "microsoft-threat-intelligence",
"type": "Vulnerability",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'attack_vector': ['Spear-phishing emails',
                   'Reflected Cross-Site Scripting (XSS)',
                   'Hidden iframe'],
 'data_breach': {'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Browser credentials',
                                              'Personally Identifiable '
                                              'Information (PII)',
                                              'Browsing history',
                                              'Screenshots',
                                              'Cookies']},
 'description': 'A recently uncovered exploit chain targeting Google Chrome '
                'and the Windows kernel has been leveraged by Chinese '
                'state-linked threat groups UTA0560 (APT31/Violet '
                'Typhoon/TA412) and JungleBamboo to deploy espionage malware '
                'and steal browser credentials. The campaign exploited '
                'zero-day vulnerabilities in Chrome and Windows, including a '
                'type-confusion flaw in Chrome’s V8 JavaScript engine, a '
                'WebAssembly sandbox-escape vulnerability, and a Windows '
                'kernel privilege-escalation flaw. Victims were lured via '
                'spear-phishing emails containing links to compromised '
                'legitimate websites with reflected XSS, leading to hidden '
                'iframes executing the exploit.',
 'impact': {'data_compromised': ['Browser credentials',
                                 'Keylogging data',
                                 'Form data',
                                 'Clipboard data',
                                 'Cookies',
                                 'Screenshots',
                                 'Browsing history'],
            'identity_theft_risk': 'High',
            'systems_affected': ['Google Chrome', 'Windows kernel']},
 'initial_access_broker': {'backdoors_established': ['GRIMWEDGE (JScript '
                                                     'backdoor)',
                                                     'LONGTALE (malicious '
                                                     'Chrome extension)'],
                           'entry_point': ['Spear-phishing emails',
                                           'Compromised legitimate websites']},
 'lessons_learned': 'The campaign underscores the criticality of rapid '
                    'patching for Chrome and Windows, as well as the need to '
                    'monitor for browser extension tampering and phishing '
                    'redirects through compromised legitimate sites.',
 'motivation': 'Espionage, Data Theft',
 'post_incident_analysis': {'corrective_actions': ['Immediate patching of '
                                                   'Chrome and Windows',
                                                   'Enhanced monitoring for '
                                                   'exploit attempts and '
                                                   'extension tampering',
                                                   'Improved phishing '
                                                   'detection for compromised '
                                                   'site redirects'],
                            'root_causes': ['Unpatched Chrome and Windows '
                                            'vulnerabilities (zero-day '
                                            'exploits)',
                                            'Patch-gap window due to delayed '
                                            'downstream patch deployment',
                                            'Reflected XSS on legitimate '
                                            'websites',
                                            'Lack of monitoring for browser '
                                            'extension tampering']},
 'recommendations': ['Apply Chrome and Windows patches immediately upon '
                     'release',
                     'Monitor for browser extension tampering',
                     'Enhance phishing detection for redirects through '
                     'compromised legitimate sites',
                     'Implement host fingerprinting detection to identify '
                     'exploit attempts'],
 'references': [{'source': 'Volexity'}],
 'threat_actor': ['UTA0560 (APT31/Violet Typhoon/TA412)', 'JungleBamboo'],
 'title': 'Chinese APT Groups Exploit Chrome and Windows Zero-Days in Targeted '
          'Espionage Campaign',
 'type': 'Espionage, Cyber Attack',
 'vulnerability_exploited': ['CVE-2026-85046 (Chrome V8 type-confusion)',
                             'CVE-2026-87491 (WebAssembly sandbox-escape)',
                             'CVE-2026-85880 (Windows kernel '
                             'privilege-escalation)']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.