# China-linked hackers exploit Chrome–Windows zero-day chain to hit NGOs and steal credentials

*Tuesday, September 15, 2026 at 6:15 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-15T06:15:11.771Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/17872.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Two China-linked hacking groups used the same previously unknown Chrome–Windows exploit chain to deploy a backdoor and a credential-stealing browser extension, security researchers report. The campaign targeted NGOs and likely broader victims, raising fresh questions about how quickly states and tech firms can close gaps in widely used software.

A pair of China-linked hacking groups quietly turned a shared software flaw into a weapon, using an unknown exploit chain in Chrome and Windows to slip into targets’ systems and plant custom malware. Security researchers say one group used the vulnerability to deploy a backdoor called GRIMWEDGE against non-governmental organizations, while another installed LONGTALE, a malicious Chrome extension built to steal credentials.

The findings center on a technical but consequential detail: an exploit chain. That term refers to multiple vulnerabilities linked together so an attacker can move from, for example, getting code to run inside a browser to gaining wider control over an operating system. In this case, both threat actors—tracked as UTA0560 and APT31—abused the same previously unknown combination of Chrome and Windows flaws to break out of the browser’s sandbox and execute their own code.

According to the published research, UTA0560 used the chain to deliver GRIMWEDGE, a backdoor that allows persistent remote access to compromised machines. NGOs were among the known targets. Once inside, GRIMWEDGE can give attackers a foothold to survey internal networks, exfiltrate documents, and potentially move laterally into more sensitive systems. APT31, a long-identified China-linked group, went in a different direction: it leveraged the same exploit path to plant LONGTALE, a Chrome extension that siphons off login credentials and other sensitive browser data.

For the people working inside those NGOs and other organizations, the immediate risk is that email accounts, cloud storage, and internal collaboration tools they rely on every day may have been quietly opened to prying eyes. A stolen password might not look as dramatic as a ransomware message, but it’s often more valuable: once an attacker can log in as a trusted user, they can read documents, track contacts, and observe strategy without triggering alarms.

Operationally, this campaign is a case study in how quickly and efficiently capable state-linked actors can weaponize holes in widely deployed software. Chrome is the dominant browser worldwide, and Windows still runs on the vast majority of desktops and laptops. A zero-day in either one is serious; a chain that spans both is a powerful instrument. By sharing—or independently discovering and exploiting—the same chain, UTA0560 and APT31 showed that once such a weapon exists, it can be used for different missions across multiple teams.

Strategically, the choice of NGOs as a confirmed target set fits a familiar pattern in China-linked cyber operations. Civil society organizations often sit on valuable political, humanitarian, and research information but have fewer resources to invest in hardened cyber defenses than governments or major corporations. Targeting them can yield insights into policy debates, advocacy campaigns, or on-the-ground reporting that state intelligence services may want to monitor or shape.

For governments and tech companies, the story is a warning that software patch cycles and threat-hunting work at different speeds. Chrome and Windows both receive frequent security updates, and vendors move quickly once a vulnerability is disclosed. But a zero-day by definition is a flaw being exploited before the vendor knows about it. When multiple well-resourced threat actors are already using the same chain, it suggests that the window between discovery and broad exploitation can be measured in weeks or months, not years.

A useful way to think about it: in today’s cyber espionage, the real high ground isn’t a single unbreakable system but the time between when an attacker finds a gap and when defenders close it. Whoever moves faster in that window wins.

What matters next is whether more victims are identified and whether details of the exploit chain prompt urgent patching and threat-hunting across governments, NGOs, and the private sector. Security teams will be looking for indicators of GRIMWEDGE and LONGTALE infections, while browser and operating system vendors work to harden their products. Any future attribution statements or diplomatic protests tying these operations more explicitly to Chinese state organs would also raise the geopolitical temperature around an attack that, for now, lives mainly in vulnerability notes and threat intel reports.
