What Happened
Volexity researchers are tracking two separate China-linked threat clusters, UTA0560 and JungleBamboo, running independent spear-phishing campaigns since September 1 that exploit the identical Chrome and Windows zero-day chain. Victims receive emails linking to legitimate university websites carrying an unpatched cross-site scripting flaw, which the attackers abuse as an open redirector toward attacker-controlled pages. Those pages chain two Chrome vulnerabilities, CVE-2026-85046 and CVE-2026-87491, with Windows kernel flaw CVE-2026-85880, breaking out of the browser sandbox and gaining code execution without further clicks. UTA0560 then deploys a JScript backdoor Volexity calls GRIMWEDGE, giving the attacker a foothold to survey the host and pull files of interest, while JungleBamboo installs a credential-stealing Chrome extension named LONGTALE instead. Volexity found the exploit code used by both groups matches byte for byte, an unusual overlap between operators it treats as unrelated, pointing to a shared exploit broker feeding multiple Chinese espionage teams at once. The campaign has targeted non-governmental organizations so far. Read the original report from The Hacker News.
Why This Matters for Canadian Organizations
Non-governmental organizations working on human rights, minority advocacy, and China-related policy issues have long sat on the target list for Chinese state-aligned espionage groups, and Canada hosts a considerable number of such organizations, alongside diaspora communities and academic researchers these campaigns often reach through the same phishing infrastructure. A shared exploit broker supplying multiple unrelated threat clusters means a patch delay against one group’s tooling leaves an organization exposed to several operators at once, raising the cost of any gap between disclosure and deployment. The university-website redirector technique also puts Canadian post-secondary institutions in an unusual position, since their own infrastructure becomes the delivery mechanism for attacks against a different set of victims entirely.
What to Do
Canadian NGOs, academic researchers, and organizations doing China-related advocacy work should confirm Chrome and Windows security updates are fully deployed, since both underlying CVEs have vendor patches available. Universities running public-facing web applications should scan for reflected cross-site scripting flaws proactively, given how effectively attackers turned trusted .edu domains into a redirection layer email security tools are less likely to flag.






