TechNewsReel
Live

China-Linked Hackers Use Chrome 'Patch Gap' to Target NGOs

Threat actors UTA0560 and APT31 deployed the 'BlueMoon' exploit chain to install backdoors and steal credentials.

TechNewsReel Newsroom · September 15, 2026

Chinese state-linked hackers launched a sophisticated spear-phishing campaign on September 1, 2026, targeting multiple non-governmental organizations (NGOs). The attackers utilized a complex exploit chain to bypass security layers in both Google Chrome and Microsoft Windows, allowing them to install malicious backdoors on victim systems.

The campaign, attributed to a threat actor tracked as UTA0560, employed a multi-stage exploit chain dubbed "BlueMoon." The attack began with spear-phishing emails that directed targets to legitimate U.S. university websites. The hackers abused a reflected cross-site scripting (XSS) vulnerability on those sites to redirect victims to their own exploit infrastructure.

BlueMoon consists of three distinct vulnerabilities: CVE-2026-85046, which allows arbitrary read/write capabilities in the Chrome V8 engine; CVE-2026-87491, used for a Chrome sandbox escape; and CVE-2026-85880, which enables code injection via Windows Advanced Local Procedure Call (ALPC). Once the chain was successfully executed, UTA0560 deployed GRIMWEDGE, a JScript-based backdoor used for system reconnaissance and the execution of remote commands.

The Chromium Patch Gap

This operation highlights a critical security failure known as the "patch gap." The vulnerabilities exploited in this campaign had already been fixed within the open-source Chromium codebase, which serves as the foundation for Google Chrome. However, because the stable release of Google Chrome lagged behind the upstream Chromium project, the fixes were not yet available to the general public. This effectively transformed known "N-day" bugs into zero-day vulnerabilities for users of the stable browser.

Security researchers noted that these patch-gap vulnerabilities present a heightened risk because they create a window for threat actors to conduct exploitation campaigns before proprietary software is updated.

Industry Implications

The incident reveals a concerning trend in the distribution of high-end cyber weapons. A second China-nexus actor, known as JungleBamboo (or APT31), was found to be using the exact same BlueMoon exploit chain. While UTA0560 deployed GRIMWEDGE, JungleBamboo used the chain to install SUPERSTOMP and a credential-stealing Chrome extension called LONGTALE.

The simultaneous use of the same sophisticated chain by two different state-linked groups suggests a maturing market for high-end exploits. It indicates that such tools may be shared or sold among different actors, significantly increasing the risk to high-value targets and NGOs who may lack the resources of large corporate security teams.

What's Next

Security teams are advised to monitor for indicators of compromise related to GRIMWEDGE and LONGTALE. While the technical details of the BlueMoon chain are now public, the overlap between UTA0560 and APT31 suggests that other state-sponsored groups may have access to similar exploit kits. Analysts will continue to monitor whether this specific chain appears in other campaigns targeting diplomatic or humanitarian sectors.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.