Skip to content
China-Linked Hackers Target NGOs with Chrome and Windows Exploits

China-Linked Hackers Target NGOs with Chrome and Windows Exploits

First seen 15 Sep 2026, 06:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 08:21 UTC
  • Chinese threat actors UTA0560 and JungleBamboo exploited Chrome and Windows vulnerabilities.
  • The attack targeted NGOs using spear-phishing emails leading to a compromised university site.
  • Three CVEs were exploited, enabling the deployment of the GRIMWEDGE backdoor.

On September 1, 2026, Chinese threat actors UTA0560 and JungleBamboo executed phishing campaigns targeting NGOs, exploiting zero-day vulnerabilities in Google Chrome and Microsoft Windows. The attack utilized a spear-phishing email that redirected victims to a compromised U.S.-based university website, leveraging a reflected XSS vulnerability. The exploit chain involved three CVEs: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, allowing attackers to gain arbitrary code execution and install the GRIMWEDGE backdoor. This malware facilitates host reconnaissance and command execution, polling a command-and-control server for further instructions. Volexity documented these operations, highlighting the use of sophisticated multi-stage exploits. The attacks were confirmed to be in progress, with active exploitation reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-01
Phishing campaigns detected
Chinese threat actors targeted NGOs using a spear-phishing campaign exploiting browser and OS vulnerabilities.
Thehackernews
2026-09-03
CVE-2026-85046 published
A vulnerability in Google Chrome was disclosed, allowing arbitrary read/write within the V8 sandbox.
Gbhackers
2026-09-04
CVE-2026-85046 added to CISA KEV
CISA listed the vulnerability for active exploitation, indicating its critical nature.
Gbhackers
2026-09-08
CVE-2026-85880 published
A vulnerability in Windows Advanced Local Procedure Call was disclosed, enabling code injection.
Gbhackers
2026-09-09
CVE-2026-87491 published
A Windows kernel privilege escalation flaw was disclosed, contributing to the exploit chain.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track APT31, GemStone and CVE-2026-85046 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed