$ techbeacon▋
CVE & Exploits

China-Linked Groups Fuse Chrome Exploit with Windows Kernel Bug in Targeted Phishing Attacks

China-Linked Groups Fuse Chrome Exploit with Windows Kernel Bug in Targeted Phishing Attacks

Security researchers have identified a coordinated campaign in which two China‑affiliated threat groups, known as UTA0560 and JungleBamboo, combined a newly discovered Google Chrome zero‑day vulnerability with a Windows kernel privilege‑escalation flaw to compromise a range of organizations, including non‑governmental organizations (NGOs). The operation was first observed by the cyber‑security firm Volexity on September 1, 2026.

According to Volexity’s analysis, the attackers began by delivering phishing emails that contained malicious links or attachments. When a victim clicked the link, the Chrome zero‑day was triggered, allowing the malicious code to execute within the browser’s process. The code then leveraged an identical Windows kernel vulnerability to elevate its privileges, granting the adversaries near‑full control over the compromised system.

The use of two distinct zero‑day exploits in a single intrusion chain marks a notable escalation in the sophistication of state‑linked cyber‑espionage groups. While Chrome zero‑day vulnerabilities have been weaponized before, pairing them with a kernel‑level privilege escalation technique is less common and suggests a concerted effort to bypass multiple layers of defense.

Targeted victims appear to be primarily NGOs, though Volexity’s report indicates that the campaign also reached other sectors. The focus on NGOs aligns with a broader pattern of espionage activity aimed at organizations that handle sensitive political, humanitarian, or environmental data. By obtaining privileged access, the attackers could exfiltrate documents, monitor communications, or install persistent backdoors for future operations.

Volexity’s findings underscore the importance of rapid patch management. Both the Chrome and Windows vulnerabilities were unpatched at the time of the attacks, highlighting the risks organizations face when they lag behind critical security updates. The firm recommends that entities enforce strict email hygiene, deploy multi‑factor authentication, and adopt endpoint detection solutions capable of spotting unusual privilege‑escalation behavior.

While the exact origins of the exploits remain undisclosed, the attribution to UTA0560 and JungleBamboo—groups previously linked to Chinese intelligence services—suggests state sponsorship. Analysts note that the timing of the campaign may be tied to geopolitical developments, though no official motive has been confirmed.

The incident adds to a growing list of high‑profile supply‑chain and zero‑day attacks that have surfaced over the past year, prompting calls for greater international cooperation on vulnerability disclosure and cyber‑norms. As researchers continue to dissect the malware payloads, additional indicators of compromise are expected to be shared with the broader security community to aid in detection and remediation.

Source: GBHackers
Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related