China‑linked hackers used shared Chrome‑Windows zero‑day chain to backdoor NGOs and steal credentials
Two China‑linked hacking groups used the same previously unknown Chrome‑Windows exploit chain, researchers report, with one deploying the GRIMWEDGE backdoor against NGOs and the other installing the LONGTALE credential‑stealing Chrome extension.
Two China‑linked threat actors exploited the same zero‑day chain in Google Chrome and Microsoft Windows to compromise targets and steal data, according to technical findings highlighted by The Hacker News.
Researchers say the shared exploit chain let attackers move from a victim’s browser into the underlying Windows system before patches were available. Both attackers were described as China‑linked but operated as distinct groups.
One group, tracked as UTA0560, used the chain to deploy a backdoor called GRIMWEDGE against non‑governmental organizations (NGOs). A backdoor of this kind lets an intruder maintain hidden access to a compromised machine and issue commands remotely.
A second group, identified as APT31, used the same chain to install a malicious Chrome extension named LONGTALE. According to the reporting, LONGTALE is designed to steal credentials from users’ browsers, giving attackers access to accounts and services that rely on those logins.
The fact that two separate China‑linked actors leveraged an identical exploit sequence across Chrome and Windows is what makes this case stand out. Zero‑day chains — previously unknown combinations of software flaws — are costly to develop and valuable because they bypass existing defenses until vendors can respond.
For NGOs and other civilian organizations, the incident underlines how widely such tools can be aimed. Staff whose daily work runs through Chrome on Windows machines can become targets even if they don’t see themselves as high‑value or political.
Signals to watch now include vendor advisories and patches for the Chrome and Windows vulnerabilities involved, any confirmation of further victim sectors beyond NGOs, and evidence that other threat groups are attempting to reuse the same exploit chain.
Sources
- OSINT