Published: · Region: Global · Category: cyber

China-linked hackers exploit Chrome–Windows zero‑day chain to infiltrate NGOs and steal credentials

Two separate China-linked groups reportedly used the same previously unknown Chrome–Windows exploit chain, one to plant a backdoor in NGOs and another to install a credential-stealing browser extension. The campaigns show how fast state-backed actors weaponize new bugs to penetrate civil society networks and quietly strip users of their digital keys.

A pair of China-linked hacking groups have been caught using the same previously unknown exploit chain targeting both Google Chrome and Microsoft Windows, in a coordinated push to infiltrate NGOs and siphon off user credentials.

According to technical research released this week, the threat cluster tracked as UTA0560 used the exploit sequence to deploy a backdoor known as GRIMWEDGE against non-governmental organizations. In parallel, an advanced persistent threat group identified as APT31 leveraged the same chain to install a Chrome extension dubbed LONGTALE, designed to steal usernames, passwords, and other login tokens directly from the browser.

The attack path relied on a so-called zero-day chain—a series of software vulnerabilities that were not publicly known or patched at the time of exploitation. By chaining a Chrome flaw with a Windows vulnerability, the attackers were able to escape the browser sandbox, gain higher-level privileges on the target machine, and then plant persistent malware or malicious extensions.

For the NGOs targeted by UTA0560, the stakes are concrete. Many handle sensitive information on activists, refugees, policy advocacy, and human-rights documentation. A stealthy backdoor such as GRIMWEDGE lets a remote operator read internal emails, copy files, monitor communications, and potentially alter documents in ways that are hard to trace. In some countries, that can expose local partners and sources to state surveillance, harassment, or worse.

LONGTALE, the credential-stealing tool used by APT31, operates closer to the daily habits of ordinary users. Once installed inside Chrome, it can capture login details for email, cloud storage, enterprise portals, and social media accounts as people type them or as tokens refresh in the background. Because the extension lives inside the browser environment, it can often bypass defenses that focus on detecting unusual logins from the outside.

Strategically, the fact that two distinct China-linked actors exploited the same chain at roughly the same time suggests either a shared source of tooling or rapid information sharing across groups. It underlines how quickly state-aligned operations can weaponize new bugs and how long they can remain effective before being discovered and patched. Each day a zero-day stays live gives attackers another 24 hours to compromise more systems and quietly expand their foothold.

Beyond the immediate victims, the campaigns point to a broader weakness: the dependence of civil society and smaller organizations on mainstream software they rarely have the resources to harden. NGOs often run on aging laptops, overburdened IT staff, and a patching cadence dictated more by daily crises than by security bulletins. When heavily resourced actors pick apart Chrome and Windows to find fresh ways in, the people least able to defend themselves are often the first ones hit.

There is a bigger lesson for governments and corporations too. Browser-based credential theft and backdoored endpoints do not stay neatly inside NGO networks. Compromised accounts can be used to impersonate trusted partners, target policymakers and journalists, and move laterally into more sensitive systems via shared cloud tools or cross-organizational collaborations.

The next things to watch are whether browser and OS vendors release and deploy patches closing the exploited vulnerabilities to a broad user base; how quickly security tools learn to flag GRIMWEDGE, LONGTALE, and similar implants; and whether incident responders uncover related campaigns using the same chain against government agencies, think tanks, or private firms. A widening victim set would confirm that the exploit was part of a broader, coordinated push rather than a handful of opportunistic hits.

Sources