Back to Intelligence

GRIMWEDGE & SUPERSTOMP 0-Day Chain: UTA0560 and JungleBamboo Exploit CVE-2026-85880 in NGO Targeting Campaign

SA
Security Arsenal Team
October 10, 2026
9 min read

Threat Summary

AlienVault OTX pulse data from October 10, 2026, surfaces a coordinated exploitation campaign in which two distinct Chinese state-linked threat actors — UTA0560 and JungleBamboo — were observed deploying an identical zero-day exploit chain against NGOs and other organizations, with confirmed targeting of entities in the United States.

The campaign, documented by Volexity, is a textbook demonstration of the "patch gap" phenomenon: the underlying vulnerabilities — CVE-2026-85046 and CVE-2026-87491 in Chrome, and CVE-2026-85880 in the Windows kernel — had already been patched in the Chromium source tree but had not yet shipped to end users. Both adversary groups exploited this window between upstream fix and downstream release, indicating either shared exploit tooling, a common upstream supplier, or deliberate coordination between clusters.

The attack chain follows a three-stage pattern:

  1. Initial Access — Spear-phishing lures directing targets to adversary-controlled infrastructure (notably the domain msbenefit.com, a masquerade designed to appear as a legitimate benefits/NGO resource).
  2. Remote Code Execution + Privilege Escalation — The chained Chrome renderer vulnerabilities (CVE-2026-85046, CVE-2026-87491) achieve code execution within the browser context, while CVE-2026-85880 provides kernel-level escalation on Windows hosts, allowing sandbox escape.
  3. Payload Delivery — Deployment of the GRIMWEDGE implant (delivered via malicious browser extension), SUPERSTOMP, and LONGTALE backdoor families for persistent access and collection.

The strategic objective is consistent with long-term intelligence collection against civil-society and NGO targets — a recurring pattern for Chinese-nexus APT operations.

Threat Actor / Malware Profile

Adversaries

UTA0560 and JungleBamboo are Chinese state-aligned intrusion sets. The shared exploit chain against the same target sector within the same timeframe strongly suggests a common exploit developer or tooling pipeline — an increasingly documented characteristic of the Chinese cyber operations ecosystem, where exploit capability is distributed to multiple operational teams.

GRIMWEDGE

  • Distribution: Delivered following successful browser exploitation; operates as a malicious browser extension, granting the actor deep visibility into victim browsing activity, session tokens, and credentials.
  • Payload behavior: Hooks browser APIs to intercept authentication material, harvest cookies, and exfiltrate webmail and cloud-console sessions.
  • Persistence: The browser extension mechanism is itself the persistence layer — surviving reboots and re-authenticating on browser launch without requiring traditional registry or service-based persistence.
  • Anti-analysis: Executes within a trusted browser process context, evading many EDR process-based detections; extension code may be obfuscated JavaScript.

SUPERSTOMP & LONGTALE

  • Role: Host-level implants deployed post-kernel-escalation via CVE-2026-85880. Because the kernel exploit grants SYSTEM-level execution, these implants can install deep persistence (services, scheduled tasks, or kernel-adjacent components) before AV/EDR policy is enforced.
  • C2 communication: HTTPS-based beaconing to attacker-registered infrastructure, including the identified domain msbenefit.com. Traffic is designed to blend with normal web activity.
  • Anti-analysis: Kernel-level initial execution defeats user-mode hooking; payloads are expected to use encrypted configurations and staged loaders (consistent with the multiple SHA256 indicator clusters in the pulse).

IOC Analysis

The pulse provides three indicator classes, each requiring a different operational handling model:

Indicator TypeExamplesOperationalization
Domainmsbenefit.comBlock at DNS resolver, web proxy, and egress firewall. Add to threat-intel platform with active blocking policy. Retro-hunt DNS query logs for at least 90 days.
CVEsCVE-2026-85046, CVE-2026-87491 (Chrome); CVE-2026-85880 (Windows kernel)These are exposure indicators, not artifacts. Feed into vulnerability management to identify hosts running Chrome/Windows builds from the unpatched window. Prioritize emergency patching.
FileHash-SHA256 (sample of 30 total)337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d, 3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f, 51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863cc, 56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951Push the full 30-hash set to EDR blocklists, mail gateway, and web proxy hash denylists. Query AV telemetry for historical file sightings across all hosts.

SOC teams should ingest the full pulse into their TIP (MISP, ThreatConnect, or Anomali) via OTX API subscription, ensuring all 30 indicators — not just the sample shown — are operationalized. Hash indicators decay quickly with recompiled payloads; the domain and CVE indicators are higher-value for retro-hunting. Note that msbenefit.com is a typosquat-style lure domain — its presence in proxy logs from NGO-facing users is a strong spear-phishing delivery signal even without payload execution.

Detection Engineering

The following detections target the campaign's core behaviors: spear-phish-driven browser exploitation, kernel-level escalation child processes, malicious extension persistence, and C2 to known infrastructure.

YAML
---
title: Chrome Exploitation Followed by Suspicious Child Process (UTA0560 / JungleBamboo)
id: 7a1f3c2e-9b44-4f1d-a5e2-202610100001
status: experimental
description: Detects Chrome spawning command shells or script interpreters, consistent with post-exploitation activity after CVE-2026-85046 / CVE-2026-87491 renderer compromise observed in the GRIMWEDGE campaign.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
    - https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
logsource:
    category: process_creation
    product: windows
detection:
    selection_parent:
        ParentImage|endswith:
            - '\chrome.exe'
    selection_img:
        Image|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
            - '\pwsh.exe'
            - '\wscript.exe'
            - '\cscript.exe'
            - '\mshta.exe'
            - '\rundll32.exe'
    condition: selection_parent and selection_img
falsepositives:
    - Rare enterprise browser extensions invoking local helpers
level: high
tags:
    - attack.execution
    - attack.t1203
    - attack.t1059
---
title: Malicious Chrome Extension Installation (GRIMWEDGE Persistence)
id: 8b2e4d3f-1c55-4a2e-b6f3-202610100002
status: experimental
description: Detects creation of new Chrome extension manifest files by non-browser processes, indicating sideloaded malicious extension persistence as used by GRIMWEDGE.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
    - https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
logsource:
    category: file_event
    product: windows
detection:
    selection_path:
        TargetFilename|contains:
            - '\Google\Chrome\User Data\'
            - '\Chromium\User Data\'
    selection_file:
        TargetFilename|endswith:
            - '\Extensions\'
            - 'manifest.json'
    filter_browser:
        Image|endswith:
            - '\chrome.exe'
    condition: selection_path and selection_file and not filter_browser
falsepositives:
    - Enterprise extension deployment via management tooling (whitelist deployment accounts)
level: high
tags:
    - attack.persistence
    - attack.t1176
---
title: Network Connection to JungleBamboo C2 Infrastructure
id: 9c3f5e4a-2d66-4b3f-c7a4-202610100003
status: experimental
description: Detects DNS resolution or network connections to known GRIMWEDGE/SUPERSTOMP command-and-control infrastructure (msbenefit.com) associated with UTA0560 and JungleBamboo.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
    - https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
logsource:
    category: dns
    product: windows
detection:
    selection:
        QueryName|contains:
            - 'msbenefit.com'
    condition: selection
falsepositives:
    - Threat research or sandbox detonation environments
level: critical
tags:
    - attack.command_and_control
    - attack.t1071.001
KQL — Microsoft Sentinel / Defender
// Hunt for GRIMWEDGE/SUPERSTOMP campaign activity: Chrome child-process exploitation,
// C2 connections to msbenefit.com, and malicious extension persistence
let C2Domain = "msbenefit.com";
let KnownHashes = dynamic([
    "337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d",
    "3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f",
    "51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863cc",
    "56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951"
]);
union isfuzzy=true
    (
    DeviceNetworkEvents
    | where TimeGenerated > ago(90d)
    | where RemoteUrl has C2Domain or RemoteUrl endswith ".msbenefit.com"
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort, ActionType, Signal="C2-Network"
    ),
    (
    DeviceProcessEvents
    | where TimeGenerated > ago(90d)
    | where InitiatingProcessFileName =~ "chrome.exe"
    | where FileName in~ ("cmd.exe","powershell.exe","pwsh.exe","wscript.exe","cscript.exe","mshta.exe","rundll32.exe")
    | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessCommandLine, Signal="Chrome-ChildProc"
    ),
    (
    DeviceFileEvents
    | where TimeGenerated > ago(90d)
    | where FolderPath has_any ("\\Google\\Chrome\\User Data\\","\\Chromium\\User Data\\")
    | where FolderPath has "\\Extensions\\" and FileName =~ "manifest.json"
    | where InitiatingProcessFileName !~ "chrome.exe"
    | project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, InitiatingProcessFileName, Signal="Extension-Persistence"
    ),
    (
    DeviceFileEvents
    | where TimeGenerated > ago(90d)
    | where SHA256 in~ (KnownHashes)
    | project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, InitiatingProcessFileName, Signal="Known-Implant-Hash"
    )
| sort by TimeGenerated desc
PowerShell
# GRIMWEDGE / SUPERSTOMP / LONGTALE IOC Hunt Script
# Checks for malicious extension persistence, C2 connections, suspicious Chrome child
# processes, scheduled-task persistence, and known implant hashes.
# Run elevated. Output written to .\grimwedge_hunt_results.txt

$Results = @()
$C2Domain = "msbenefit.com"
$KnownHashes = @(
    "337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d",
    "3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f",
    "51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863cc",
    "56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951"
)

Write-Host "[*] Checking for live connections to JungleBamboo C2 ($C2Domain)..." -ForegroundColor Cyan
$dnsCache = Get-DnsClientCache -ErrorAction SilentlyContinue | Where-Object { $_.Entry -like "*$C2Domain*" }
if ($dnsCache) { $Results += "[ALERT] DNS cache hit for C2: $($dnsCache.Entry -join ', ')" }

Write-Host "[*] Scanning Chrome extension directories for suspicious manifests..." -ForegroundColor Cyan
$extPaths = @("$env:LOCALAPPDATA\Google\Chrome\User Data", "$env:LOCALAPPDATA\Chromium\User Data")
foreach ($base in $extPaths) {
    if (Test-Path $base) {
        Get-ChildItem -Path $base -Recurse -Filter "manifest.json" -ErrorAction SilentlyContinue |
            Where-Object { $_.FullName -like "*\Extensions\*" } | ForEach-Object {
                $mtime = $_.LastWriteTime
                $content = Get-Content $_.FullName -Raw -ErrorAction SilentlyContinue
                if ($content -match 'cookies|webRequest|<all_urls>|tabs' -and $mtime -gt (Get-Date).AddDays(-120)) {
                    $Results += "[SUSPICIOUS] Extension manifest: $($_.FullName) | Modified: $mtime"
                }
                $hash = (Get-FileHash $_.FullName -Algorithm SHA256).Hash
                if ($KnownHashes -contains $hash.ToLower()) {
                    $Results += "[CRITICAL] Known implant hash match: $($_.FullName)"
                }
            }
    }
}

Write-Host "[*] Reviewing scheduled tasks for implant persistence..." -ForegroundColor Cyan
Get-ScheduledTask | Where-Object { $_.TaskPath -notlike "\Microsoft*" } | ForEach-Object {
    $action = ($_.Actions | Select-Object -First 1).Execute
    if ($action -match 'powershell|cmd.exe|wscript|rundll32' ) {
        $Results += "[REVIEW] Non-Microsoft scheduled task: $($_.TaskName) -> $action"
    }
}

Write-Host "[*] Checking Run keys for persistence artifacts..." -ForegroundColor Cyan
$runKeys = @("HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run",
             "HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run")
foreach ($rk in $runKeys) {
    if (Test-Path $rk) {
        (Get-ItemProperty $rk).PSObject.Properties | Where-Object {
            $_.Value -match 'AppData|Temp|ProgramData' -and $_.Name -notmatch '^PS'
        } | ForEach-Object { $Results += "[REVIEW] Run key: $rk\$($_.Name) = $($_.Value)" }
    }
}

if ($Results.Count -eq 0) { Write-Host "[+] No IOC hits detected on this host." -ForegroundColor Green }
else {
    $Results | Out-File .\grimwedge_hunt_results.txt
    Write-Host "[!] $($Results.Count) findings written to .\grimwedge_hunt_results.txt" -ForegroundColor Red
    $Results | ForEach-Object { Write-Host $_ -ForegroundColor Yellow }
}

Response Priorities

Immediate (0–4 hours)

  • Block msbenefit.com at DNS, proxy, and egress firewall; enable retroactive DNS log search back 90 days.
  • Push all 30 SHA256 indicators from the OTX pulse to EDR blocklists and mail/web gateway hash denylists.
  • Emergency-patch Chrome across the fleet to a build that includes fixes for CVE-2026-85046 and CVE-2026-87491; patch Windows for CVE-2026-85880. Identify any hosts still on vulnerable builds via software inventory.
  • Hunt for Chrome child-process execution using the Sigma rule and KQL query above — this is the highest-fidelity post-exploitation signal.

Within 24 Hours

  • Audit installed browser extensions fleet-wide (the GRIMWEDGE persistence vector). Enforce extension allowlisting via Chrome enterprise policy (ExtensionInstallAllowlist / ExtensionInstallBlocklist).
  • Force re-authentication and revoke active sessions for users whose browsers resolved msbenefit.com — extension-based cookie theft enables session hijacking without password compromise. Invalidate OAuth tokens for cloud consoles and webmail.
  • Review scheduled tasks and Run keys on hosts with any hit; SUPERSTOMP/LONGTALE persistence survives reboot and may outlive browser patching.
  • Escalate any confirmed implant hash match to full IR: isolate host, acquire memory and disk, and assume kernel-level compromise.

Within 1 Week

  • Close the patch-gap structurally: implement auto-update enforcement for Chrome with a maximum 72-hour drift policy; track Chromium source-to-release lag as a formal risk metric.
  • Deploy browser isolation for high-risk NGO/civil-society-facing staff and any user populations handling sensitive beneficiary or advocacy data.
  • Harden kernel attack surface: enable HVCI/VBS where hardware supports it to raise the cost of CVE-2026-85880-class kernel escalation.
  • Brief leadership on the shared-tooling finding: two distinct Chinese APT clusters using one exploit chain implies an upstream exploit supplier — expect CVE-2026-85880-class kernel exploits to proliferate to additional actors.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.