Chrome–Windows zero‑day exploited against NGOs as China‑linked hackers widen cyber pressure
Two China-linked hacking groups used the same undisclosed Chrome–Windows exploit chain to plant spyware and credential-stealing tools, including against nongovernmental organizations. The coordinated use of a zero-day attack path shows how quickly state-backed actors can weaponize browser flaws into strategic intelligence collection.
Two China-linked hacking groups have been caught using the same previously unknown exploit chain in Google Chrome and Microsoft Windows to install surveillance tools, including against NGOs, in a sign of how fast state-backed actors are folding new software flaws into their operations. Security researchers say the overlap points to either shared tooling or rapid copycat use of a highly valuable access method.
One group, tracked as UTA0560, used the exploit chain to deploy a backdoor nicknamed GRIMWEDGE against nongovernmental organizations. A second group, associated with the well-known APT31 cluster, used the same chain to install LONGTALE, a malicious Chrome extension designed to steal credentials. Both operations leveraged a Chrome–Windows zero-day combination, meaning the software makers had not yet issued patches when the attacks occurred.
For the targeted NGOs, the stakes go beyond nuisance malware. A backdoor like GRIMWEDGE can give attackers persistent access to internal networks, sensitive communications, and contact lists. A credential-stealing extension such as LONGTALE can harvest login details for email, cloud storage, and collaboration platforms. In the hands of a capable intelligence service, that kind of access can expose dissidents, compromise sources, and map entire advocacy networks.
Technically, using a shared exploit chain against different targets suggests a campaign focused on maximizing the value of a rare offensive asset. Zero-day chains that can reliably break out of the browser sandbox and gain higher system privileges are expensive to develop, whether through in-house research or purchase from commercial exploit brokers. Deploying the same chain in parallel by more than one threat actor underscores both its potency and the strategic importance Beijing-linked operators place on browser-based entry points.
At a strategic level, these operations show how traditional boundaries between espionage, influence, and domestic control blur in cyberspace. China-linked groups have been repeatedly accused of targeting not only foreign governments and companies but also NGOs, think tanks, and civil-society organizations that research human rights, governance, and security. By compromising such organizations, attackers can track narratives, anticipate criticism, and potentially shape the information environment abroad and at home.
For governments and large institutions, the shared exploit chain is another reminder that cyber defense can’t rely solely on patching known bugs. Even up-to-date systems were vulnerable until the Chrome and Windows zero-days were discovered and fixed. Organizations whose staff live in the browser—journalists, policy researchers, humanitarian workers—face a particular exposure when browser-based exploits become a favored tool of state-linked actors.
The fact that one of the payloads was a Chrome extension is also telling. Browser extensions often sit in a blind spot for both users and security teams: they’re installed once, updated automatically, and granted sweeping access to web activity. A malicious extension like LONGTALE can quietly siphon off passwords and session cookies without triggering obvious alarms, especially if it masquerades as a legitimate helper add-on.
A key takeaway from this case is blunt: the modern workday browser has become an intelligence target as valuable as any classified terminal, because that’s where the world’s authentication tokens, documents, and private conversations now live.
Signals to watch going forward include whether more China-linked or other state-aligned groups are found using the same exploit chain, how quickly Chrome and Windows vendors roll out and enforce patches, and whether NGOs and policy organizations change their security posture—tightening extension controls, hardening browser configurations, and segmenting sensitive work away from general-purpose web tools.
Sources
- OSINT