Published: · Region: Global · Category: cyber

China‑linked hackers exploit Chrome‑Windows zero‑day chain against NGOs, exposing global cyber blind spot

Two China‑linked hacking groups used the same undisclosed Chrome‑Windows exploit chain to quietly compromise NGOs and steal browser credentials, researchers report. The campaign shows how a single unpatched path can let multiple state‑aligned actors burrow into civil society networks worldwide.

Two China‑linked threat actors have been caught using the same previously unknown exploit chain against Chrome and Windows to break into targets and plant custom tools, in a case that exposes how fast high‑end hacking techniques can spread once they exist. One group, tracked as UTA0560, used the chain to deploy a backdoor dubbed GRIMWEDGE against non‑governmental organizations. Another, the long‑watched APT31, leveraged it to install a malicious Chrome extension called LONGTALE designed to steal credentials from victims’ browsers.

The exploit chain hit both the browser and the operating system, giving attackers a powerful route from a simple web interaction to deep control over a machine. Details published by security researchers on 15 September describe how the same sequence of vulnerabilities was woven into separate campaigns with different payloads but the same end goal: persistent, hard‑to‑detect access to sensitive networks.

For the NGOs targeted by UTA0560, the practical impact goes far beyond a compromised laptop. Many rely on email, document sharing and messaging platforms accessed through Chrome for work on human rights, governance and conflict monitoring. A backdoor like GRIMWEDGE sitting behind that daily activity means attackers could quietly watch case files, informant communications, funding flows or internal strategy for months.

APT31’s use of LONGTALE shows a parallel focus on the keys that unlock wider systems. By installing a credential‑stealing extension inside Chrome, the group positioned itself to capture usernames, passwords and session tokens as users logged into cloud accounts or internal portals. Those stolen credentials can then be used to move laterally through organizations without triggering the alarms that a more obvious piece of malware might trip.

Technically, what makes this episode troubling for defenders is not just that a Chrome‑Windows chain existed, but that more than one well‑resourced group appears to have had access to it. That raises the possibility that the vulnerability information was shared, brokered or independently discovered within a relatively tight time frame. In any of those scenarios, it’s a reminder that there is no such thing as a boutique, one‑off exploit once top‑tier actors are involved; capabilities diffuse.

Strategically, the choice of targets fits a broader pattern of Chinese cyber activity. State‑aligned groups have consistently gone after NGOs, think tanks and advocacy organizations that track Beijing’s domestic policies, foreign influence and regional assertiveness. Those networks may seem peripheral compared with government ministries or defense firms, but they often hold early drafts of policy papers, confidential interviews and dissident communications that governments are keen to see.

For civil society, the cost is both operational and psychological. Organizations that already work in high‑risk environments must now assume that simply using mainstream software like Chrome and Windows can expose staff and contacts if updates lag even briefly or if unknown flaws exist. That reality forces small teams to devote scarce resources to security they may not fully understand, or else accept that their work may be conducted under hostile surveillance.

One clear takeaway is that patching alone is not enough when adversaries are exploiting zero‑days—vulnerabilities that vendors haven’t yet fixed. Defense now depends on layering browser and endpoint protections, monitoring odd browser extensions or traffic, and assuming that some compromises will occur despite best efforts. The key questions for governments and NGOs in the coming days are whether browser and OS vendors have fully closed the gaps described by researchers, whether signs of the GRIMWEDGE and LONGTALE toolsets appear in more networks, and whether any public attribution by Western officials escalates diplomatic friction with Beijing over cyber‑enabled espionage.

Sources