#spearphishing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #spearphishing, aggregated by home.social.
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
In September 2026, two Chinese threat actors, UTA0560 and JungleBamboo, were observed exploiting an identical Chrome zero-day vulnerability chain targeting NGOs and other organizations. The exploitation leveraged CVE-2026-85046 and CVE-2026-87491 in Chrome alongside CVE-2026-85880 in Windows kernel. These vulnerabilities had been patched in Chromium source code but not yet released to Chrome users, creating a patch-gap exploitation window. UTA0560 conducted spear-phishing campaigns using financial lures to deliver GRIMWEDGE JScript backdoor for reconnaissance and command execution. JungleBamboo employed generic phishing themes to deploy SUPERSTOMP loader, which installed the LONGTALE Chrome extension designed for credential theft, keylogging, and surveillance. Both actors used byte-for-byte identical shellcode, suggesting a shared exploit supply chain while deploying distinct post-exploitation tools tailored to their operational objectives.
Pulse ID: 6aa2707076e8a9dd36706bde
Pulse Link: https://otx.alienvault.com/pulse/6aa2707076e8a9dd36706bde
Pulse Author: AlienVault
Created: 2026-09-10 08:55:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#0Day #BackDoor #Chinese #Chrome #ChromeExtension #CyberSecurity #Edge #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ShellCode #SpearPhishing #SupplyChain #Vulnerability #Windows #ZeroDay #bot #AlienVault
-
BigBear 2.0: la piattaforma di phishing-as-a-service che aggira anche l’MFA di Microsoft 365
CloudSEK smaschera BigBear 2.0, un kit AiTM basato su Evilginx2 che ha compromesso 258 organizzazioni in 40 paesi, rubando 474 sessioni con secondo fattore già superato e disabilitando via JavaScript le chiavi di sicurezza FIDO2/WebAuthn.