StratosAlly – Cybersecurity for digital safety

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy Malware

Picture of StratosAlly

StratosAlly

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy Malware

A newly uncovered cyber-espionage campaign is turning a simple phishing email into a full compromise of Google Chrome and Windows systems.

Researchers at Volexity have linked the campaign to a China-associated threat actor that exploited a chain of two Chrome vulnerabilities and one Windows flaw to deliver malware to targeted organizations. The activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. 

The attacks begin with a carefully crafted spear-phishing email. Instead of sending victims directly to an obviously malicious domain, the attackers used a legitimate U.S. university website containing a reflected cross-site scripting (XSS) vulnerability. Clicking the link redirected victims to attacker-controlled infrastructure hosting the exploit chain. 

The exploit, tracked as BlueMoon, chained three vulnerabilities: CVE-2026-85046 and CVE-2026-87491 in Chrome’s V8 engine, followed by CVE-2026-85880 in Windows’ Advanced Local Procedure Call (ALPC). Together, the flaws allowed attackers to escape Chrome’s security sandbox and execute code on the underlying Windows system. 

One campaign used the chain to deploy GRIMWEDGE, a JavaScript-based backdoor capable of gathering system information, listing files and processes, executing commands, and downloading additional payloads. Researchers also observed another China-linked actor using the same exploit chain to deploy SUPERSTOMP, which installed a malicious Chrome extension known as LONGTALE/GemStone. 

The extension disguised itself as a legitimate Google Gemini add-on while quietly enabling keylogging, form capture, cookie and session theft, screenshots, and data collection.

What makes the campaign particularly concerning is how quickly the same exploit chain appeared across multiple threat groups. Researchers believe the kit may have been shared or commercially distributed, lowering the barrier for other attackers to weaponize the vulnerabilities. 

Let’s refine your stalking skills; go through our Instagram and LinkedIn.

more Related articles