Back to advisories

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

Chinese threat actor UTA0560 is exploiting Chrome and Windows zero-days in coordinated attacks against NGOs using spear-phishing and reflected XSS on compromised university sites. Victims receive malicious redirects that deploy GRIMWEDGE, a JavaScript backdoor enabling reconnaissance and further compromise. This is a live campaign with no public patches available.

CRITICALAdvisorySep 16, 2026
Action required
Immediately hunt for GRIMWEDGE indicators in browser processes and JavaScript execution logs. Monitor for suspicious Chrome crashes, unexpected child processes from browser engines, and beaconing to unknown C2 infrastructure. Isolate any affected systems and preserve forensics.
Affected products
Google ChromeMicrosoft Windows