China-linked hackers exploit Chrome–Windows zero-day chain to spy on NGOs and steal credentials
Two separate China‑linked hacking groups used the same previously unknown Chrome–Windows exploit chain to deploy custom malware and a credential‑stealing browser extension. The campaigns targeted NGOs and other victims, showing how quickly sophisticated zero‑day tools are being shared and reused against civil society and potentially government networks.
Two China‑linked hacking groups have been caught using the same chain of previously unknown vulnerabilities in Google Chrome and Microsoft Windows to break into targets, plant backdoors and steal login credentials, in a case that illustrates how prized zero‑day exploits can rapidly spread across espionage operations.
Security researchers reported that a cluster tracked as UTA0560 leveraged the exploit chain to deploy a backdoor dubbed GRIMWEDGE against non‑governmental organizations. A second, separate group commonly referred to as APT31 used the same vulnerabilities to install a malicious Chrome extension called LONGTALE, designed to harvest user credentials. Both groups are assessed by multiple security firms as having links to China based on infrastructure, tooling and past targeting patterns.
The core of the operation was a so‑called zero‑day chain: a sequence of security flaws in widely used software that had not yet been publicly disclosed or patched by the vendors. By combining a Chrome bug with a Windows vulnerability, the attackers were able to first gain code execution through the browser and then escape the normal sandbox protections to take deeper control of the system. That allowed them to quietly drop GRIMWEDGE or install the LONGTALE extension without triggering standard user prompts.
For the NGOs in the crosshairs, the implications are serious. These organizations often handle sensitive information about conflict zones, human rights investigations, or policy debates that foreign intelligence services would value. Yet they rarely have the hardened cybersecurity budgets of governments or large corporations. A malicious credential‑stealing extension like LONGTALE can silently siphon passwords to email, cloud storage, or internal tools, giving attackers a foothold that persists even if the initial exploit is later patched.
Operationally, the fact that two distinct China‑linked actors used the same exploit chain is a major part of the story. It suggests either a shared supplier of zero‑day tools, internal sharing within a broader ecosystem, or at minimum rapid replication once one team’s methods became known to another. For defenders, that turns what might have been a narrow, hard‑to‑spot campaign into a wider risk: the same technical doorway is being tried by different intruders with different mission sets.
At a strategic level, the episode underscores how civilian and quasi‑civilian targets are now routine in state‑aligned cyber operations. NGOs, advocacy groups and think tanks not only shape public narratives; they often maintain direct channels to diplomats and lawmakers. Penetrating those networks can give a foreign government insight into negotiation positions, activist plans, or upcoming reports that might embarrass allies or expose abuses.
This kind of exploit reuse also sharpens the policy debate over how governments should handle the zero‑day market. When a single bug chain in the Chrome–Windows stack can be weaponized by multiple espionage units, the cost of delayed disclosure isn’t theoretical; it’s felt by every unpatched user whose browser quietly becomes an entry point for foreign intelligence.
The shareable lesson here is simple: in a world where browsers are operating systems in their own right, a single unpatched vulnerability can turn an NGO’s laptop into a listening post for a foreign state.
In the near term, the key signals to watch are vendor advisories and updates from Google and Microsoft, evidence of broader scanning or exploitation beyond NGOs, and whether additional China‑linked or other state‑aligned groups are found reusing the same chain. Monitoring for new detections of GRIMWEDGE or LONGTALE in government, media or corporate networks will help show whether this campaign remains narrowly focused or has already jumped into the wider digital ecosystem.
Sources
- OSINT