Back to Intelligence

GRIMWEDGE/SUPERSTOMP Chrome-Windows 0-Day Chain + Djinn Stealer/TaskWeaver Credential Raid: OTX Detection Pack

SA
Security Arsenal Team
October 10, 2026
8 min read

1. Threat Summary

The two OTX pulses show a convergent credential-theft problem from different intrusion paths: a high-end browser/kernel exploit chain and a lower-friction loader/stealer pipeline. The Volexity-reported activity attributed to UTA0560 and JungleBamboo chained CVE-2026-85046 and CVE-2026-87491 in Chrome with CVE-2026-85880 in the Windows kernel, exploiting a patch-gap window in which Chromium source fixes existed but stable Chrome builds had not shipped. Targeting centered on NGOs and U.S.-linked organizations, with spear-phishing, browser extension abuse, and the malware families GRIMWEDGE, SUPERSTOMP, and LONGTALE. The domain msbenefit.com is the clearest network lure/C2 anchor in the provided indicator set.

The second pulse highlights Djinn Stealer, a cross-platform information stealer delivered as a second stage by the TaskWeaver Node.js loader and associated with SimpleHelp exploitation via CVE-2026-48558. Its collection model is rules-based and developer-infrastructure aware: cloud platforms, source control, package registries, infrastructure tooling, AI coding assistants, browsers, SSH material, and cryptocurrency wallets. Collectively, these pulses suggest attackers are optimizing for identity and secret material: session cookies, tokens, SSH keys, cloud credentials, CI/CD secrets, wallet keys, and endpoint privilege escalation. Treat exposed developer workstations, NGO executive mailboxes, unmanaged remote access tooling, and out-of-date Chrome builds as priority blast-radius controls.

2. Threat Actor / Malware Profile

UTA0560 and JungleBamboo are assessed as China-nexus operators sharing or independently acquiring the same Chrome/Windows exploit chain. The tradecraft pattern is patch-gap exploitation: observe a Chromium security fix, weaponize before stable release, then combine a browser renderer escape with Windows kernel elevation via CVE-2026-85880. GRIMWEDGE, SUPERSTOMP, and LONGTALE should be treated as modular intrusion tooling rather than single commodity stealers; expected behaviors include staged payload retrieval after spear-phish or drive-by, persistence through browser extension components or scheduled tasks, credential/session harvesting, and C2 over HTTPS using plausible-benign domains such as msbenefit.com. Anti-analysis likely includes environment checks, delayed execution after user interaction, encrypted configuration, and separation between initial downloader, privilege-escalation component, and final espionage/collection module.

Djinn Stealer with TaskWeaver is more operationally portable. TaskWeaver uses Node.js loader logic to blend into developer and IT admin environments, then deploys Djinn as a second-stage collector. Distribution appears tied to SimpleHelp exploitation or exposed remote support paths, but the same loader can be repackaged through malicious npm packages, trojanized admin utilities, fake updates, or post-exploitation download cradles. Djinn's rules engine is the differentiator: it targets cloud config files, Git and package registry tokens, SSH private keys, browser credential stores, infrastructure-as-code state, AI assistant session data, and crypto wallets, then archives results for exfiltration. Persistence may be minimal on endpoints because value comes from rapid secret theft; however, defenders should still check Run keys, scheduled tasks, Chrome extension directories, Node global paths, and remote-access service configuration changes. Expected anti-analysis includes base64 or obfuscated JavaScript, process injection into trusted browsers, use of signed tools such as node.exe, and cleanup of staged archives after HTTPS exfiltration.

3. IOC Analysis

The indicator set is hash-heavy, with four SHA256 values in the exploit-chain pulse and one SHA256 for Djinn/TaskWeaver: 337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d, 3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f, 51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863cc, 56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951, and f4a72600a3735c2a4d843875ea61bbb6f935a1af51a81f2fbc992ce11ba94afc. Operationalize hashes through EDR blocklists, MDE custom indicators, VTI lookups, and retrohunts across email detonation, browser cache, downloads, temp directories, and software inventory. Do not rely on hashes alone: patch-gap chains rotate payloads quickly.

The domain msbenefit.com should be blocked at DNS, web proxy, TLS SNI inspection where lawful, and EDR network indicators; hunt historical DNS, proxy, firewall, and EDR telemetry before assuming compromise is current. CVEs CVE-2026-85046, CVE-2026-87491, CVE-2026-85880, and CVE-2026-48558 are vulnerability-context indicators rather than blocking artifacts. Map them to asset exposure: Chrome stable lag, Windows kernel patch level, Chromium-based browsers, and SimpleHelp or similar remote support servers. SOC tooling that decodes and enriches these indicators includes MDE/Sentinel for process-network joins, Splunk or Elastic for proxy/DNS retrohunts, Velociraptor for artifact collection, YARA for memory/disk triage, and sandbox detonation for extension and Node loader behavior. Prioritize identity telemetry: impossible travel, token replay, OAuth consent grants, cloud key creation, Git package registry logins, and SSH authentication anomalies after any host hit.

4. Detection Engineering

YAML
---
title: Chrome Patch Gap Exploit Child Process and Benefit Domain C2
id: 6f2c7b10-6d0e-4d2f-9c0a-ota-chrome-patchgap-0001
status: experimental
description: Detects suspicious Chrome renderer or update processes spawning script shells, Windows utilities, or extension-side loaders followed by network contact to the reported benefit-themed C2 domain.
references:
  - https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
author: Security Arsenal
date: 2026/10/10
tags:
  - attack.initial_access
  - attack.privilege_escalation
  - attack.command_and_control
  - attack.t1189
  - attack.t1059
  - attack.t1546
logsource:
  category: process_creation
  product: windows
detection:
  selection_browser_parent:
    ParentImage|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\brave.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\node.exe'
  filter_common:
    CommandLine|contains:
      - 'chrome://extensions'
      - '--type=renderer'
  condition: selection_browser_parent and selection_child and not filter_common
falsepositives:
  - Enterprise browser management tools that legitimately launch PowerShell for policy or extension inventory.
level: high
---
title: TaskWeaver Node Loader to Djinn Secret Collection
id: 0c6f4f7e-1a0d-4dc7-8a51-ota-djinn-taskweaver-0002
status: experimental
description: Detects node.exe or script interpreters reading credential, cloud, Git, package registry, SSH, browser, wallet, or AI-assistant configuration locations followed by archive or network staging behavior.
references:
  - https://blackpointcyber.com/blog/threat-snapshot-djinn-stealer/
author: Security Arsenal
date: 2026/10/10
tags:
  - attack.credential_access
  - attack.collection
  - attack.exfiltration
  - attack.t1552
  - attack.t1560
  - attack.t1041
logsource:
  category: process_creation
  product: windows
detection:
  selection_loader:
    Image|endswith:
      - '\node.exe'
      - '\npm.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
  selection_secret_paths:
    CommandLine|contains:
      - '/.ssh/'
      - '/.aws/credentials'
      - '/.azure/'
      - '/.config/gcloud/'
      - '/.npmrc'
      - '/.git-credentials'
      - '/.docker/config.json'
      - '/AppData/Local/Google/Chrome/User Data/'
      - '/AppData/Roaming/Code/User/'
      - 'wallet'
      - 'metamask'
      - 'exodus'
      - 'Login Data'
  selection_stage:
    CommandLine|contains:
      - 'Compress-Archive'
      - 'tar.exe'
      - '7z.exe'
      - 'rar.exe'
      - 'Invoke-WebRequest'
      - 'curl.exe'
      - 'certutil'
      - 'bitsadmin'
  condition: selection_loader and selection_secret_paths and selection_stage
falsepositives:
  - Developer backup scripts, dotfile synchronization, and legitimate Node CLI tooling that reads cloud configuration.
level: high
KQL — Microsoft Sentinel / Defender
let Hashes = dynamic(['337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d','3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f','51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863cc','56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951','f4a72600a3735c2a4d843875ea61bbb6f935a1af51a81f2fbc992ce11ba94afc']);
let SecretTerms = dynamic(['/.ssh/','/.aws/credentials','/.azure/','/.config/gcloud/','/.npmrc','/.git-credentials','Login Data','wallet','metamask','AI assistant']);
let Net = DeviceNetworkEvents
| where Timestamp > ago(14d)
| where RemoteUrl contains 'msbenefit.com' or RemoteIP in (externaldata(type:string)[Indicator:string] with (format='txt'))
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort;
let Proc = DeviceProcessEvents
| where Timestamp > ago(14d)
| where SHA256 in (Hashes)
   or (InitiatingProcessFileName in~ ('chrome.exe','msedge.exe') and FileName in~ ('powershell.exe','cmd.exe','rundll32.exe','regsvr32.exe','node.exe','mshta.exe'))
   or (FileName in~ ('node.exe','npm.exe','powershell.exe','pwsh.exe') and ProcessCommandLine has_any (SecretTerms));
union Net, Proc
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), Signals=count(), SampleCommand=any(InitiatingProcessCommandLine), SampleRemote=any(RemoteUrl) by DeviceName, InitiatingProcessFileName, FileName, SHA256
| sort by LastSeen desc;
PowerShell
$ErrorActionPreference = 'SilentlyContinue'
$hashes = @('337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d','3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f','51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863cc','56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951','f4a72600a3735c2a4d843875ea61bbb6f935a1af51a81f2fbc992ce11ba94afc')
$paths = @("$env:TEMP","$env:LOCALAPPDATA\Google\Chrome\User Data","$env:APPDATA\npm","$env:USERPROFILE\Downloads","C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp")
Write-Host '=== Network indicators ==='
Get-NetTCPConnection | Where-Object {$_.RemoteAddress -ne ''} | Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,State,OwningProcess,@{n='Process';e={(Get-Process -Id $_.OwningProcess).ProcessName}} | Format-Table -AutoSize
Resolve-DnsName msbenefit.com | Format-Table -AutoSize
Get-DnsClientCache | Where-Object {$_.Entry -like '*msbenefit.com*'} | Format-Table -AutoSize
Write-Host '=== Suspicious persistence ==='
Get-ItemProperty 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Run','HKCU:\Software\Microsoft\Windows\CurrentVersion\Run' | Select-Object PSPath,* | Format-List
Get-ScheduledTask | Where-Object {$_.Actions.Execute -match 'node|powershell|chrome|rundll32|wscript' -and $_.TaskPath -notlike '\Microsoft\*'} | Select-Object TaskName,TaskPath,State | Format-Table -AutoSize
Get-ChildItem "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Extensions" -ErrorAction SilentlyContinue | Select-Object FullName,LastWriteTime | Format-Table -AutoSize
Write-Host '=== Hash sweep in likely staging paths ==='
foreach ($p in $paths) {
  if (Test-Path $p) {
    Get-ChildItem $p -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
      $h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
      if ($hashes -contains $h) { Write-Host "MATCH: $($_.FullName) $h" }
    }
  }
}
Write-Host '=== Secret locations touched by risk processes ==='
Get-Process node,npm,chrome,msedge,powershell,pwsh -ErrorAction SilentlyContinue | Select-Object Id,ProcessName,Path,StartTime,CommandLine | Format-List

5. Response Priorities

Immediate: block msbenefit.com and the listed SHA256 values at DNS, proxy, EDR, email gateway, and cloud egress controls. Isolate any endpoint with chrome.exe or node.exe spawning script shells, unexpected scheduled tasks, unknown Chrome extensions, or access to SSH, cloud, Git, npm, browser, or wallet secret stores. Confirm Chrome and Chromium-based browsers are on the fixed stable build and Windows kernel patching for CVE-2026-85880 is deployed; treat SimpleHelp and other remote access platforms as internet-facing critical assets until CVE-2026-48558 exposure is closed.

Within 24 hours: assume credential exposure on any host matching the behavior, not only the hash. Force password resets, revoke browser sessions, rotate OAuth tokens, invalidate cloud access keys, regenerate SSH keys, rotate npm/GitHub/GitLab/Azure/AWS/GCP tokens, review AI assistant connected-app grants, and inspect crypto wallet transaction history for unauthorized movement. Review identity logs for token replay, new device enrollment, MFA fatigue, mailbox forwarding, OAuth consent, service principal key creation, and CI/CD secret reads. Preserve memory and browser artifacts before rebuilding.

Within one week: harden architecture against the vector. Enforce browser version compliance and rapid patch rings, disable unapproved extensions, separate admin and developer browsing from credential stores, require phishing-resistant MFA, conditional access and token binding for cloud control planes, short-lived credentials for CI/CD, egress filtering by category and ASN reputation, application control for Node outside approved developer workspaces, vulnerability management SLAs for browser/kernel patch gaps, and detection content regression tests for future OTX pulse ingestion.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.