Patch Gap Zero Day Chain: Three Chinese Actors Share a Chrome and Windows Kernel Exploit Kit
Source report →A spear-phishing campaign detected on September 1, 2026 led to the discovery of a three-stage exploit chain targeting Google Chrome and the Windows kernel. The first Chrome flaw had already been fixed in Chromium source code but had not yet reached a stable Chrome release, creating a window in which the vulnerability was effectively a zero-day for Chrome users while the patch was publicly visible. Investigators assessed with medium confidence that the exploit developer identified the flaw by reverse-engineering that public fix.
The chain begins with a V8 type confusion that provides arbitrary read and write inside the V8 sandbox, followed by a WebAssembly flaw used to escape it and a previously unknown Windows kernel vulnerability used to escape the Chrome renderer sandbox and inject into the browser process. Delivery uses a lure page, an obfuscated JavaScript loader that checks for Chrome on Windows, and a hidden exploit page containing Base64-encoded shellcode for host reconnaissance, kernel privilege escalation, and browser-process injection. The exploit includes retry logic, environment checks, development parameters, and a configurable payload URL, allowing the same core exploit to deliver different malware.
The actors diverged after gaining execution inside the Chrome browser process. One deployed a DLL side-loading chain with scheduled-task persistence, then delivered an MSI-based JScript backdoor that operated in memory and supported reconnaissance, file operations, process control, uploads, and arbitrary execution. A second actor installed the LONGTALE Chrome extension, masquerading as a Google Gemini add-on, to capture keystrokes, form data, cookies, browser storage, and targeted screenshots. LONGTALE had no command-execution capability and instead functioned as a credential and session harvester. The LONGTALE installer bypassed Chrome's extension integrity protections by modifying the profile's `Secure Preferences` file, removing newer encrypted integrity values, inserting the malicious extension, and generating valid legacy authentication codes. Chrome then accepted the forged state and re-signed it under the newer integrity scheme. The actor also hid its command-and-control infrastructure behind Cloudflare Tunnels.
A third actor used the same exploit kit two days later through typosquatted websites that mirrored legitimate content while loading the exploit in a hidden iframe. Its reconnaissance and privilege-escalation stages matched the earlier activity, but the final stage downloaded and launched the implant in-process through the Windows shell rather than using `cmd.exe` and a transfer utility. The implant established scheduled-task persistence and supported command execution, process discovery, file transfer, and beacon object file execution. Additional observations by other vendors indicate that the exploit kit was shared and customized across multiple threat groups rather than being exclusive to a single actor.
IOCs (38)
Scan your environment for IOCs →SHA256 FILE HASH 14
7a52ff23949edee8faa61ce0def6dbca8b7e5943c54d23376cc190762ea3985ccd0c21f9b32b7feeda1787fccab622dec60ecdf84c0538c08bde3946856b0fa0b7b0cd6539464ab39c6526e499f86d611faa21c5af945535ebaf187cec543af15995f42a828606705a7339d58a665c229936e81c4e539cdfa115eb46a2eb53d651462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863ccd17053557bb90298f7b115432b4820a248fdbe678bca31721529b1f51a82343b337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c95159dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcbe2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c05eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e38858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cbSHA1 FILE HASH 1
668aa5551315ab26b67118fbb29f8e4560a1e1afMD5 FILE HASH 1
177652713dad3c128bd9195abf2b7603DOMAIN 14
cloud.shinewrist[.]netocr[.]opusaccel[.]topgitprogram[.]commsbenefit[.]comdocument.gitprogram[.]comamericanprgoress[.]topchinadigitaltimes[.]topthecovnresation[.]comthecovnresation[.]netpersonclouds[.]comborneobulletins[.]topoutsourcingwise[.]nethalal-navi[.]nethalaltak[.]netIP ADDRESS 2
206.166.251[.]16496.9.125[.]52EMAIL 1
ircribbin77@hotmail[.]comURL 5
https://photos.msbenefit[.]com/fa/t3https://photos.msbenefit[.]com/fb/w3zhttps://proof.gitprogram[.]com/a4/j8https://xyz0102.gitprogram[.]com/a001https://americanprgoress[.]top/chrome_cleanup.exeDetections (10)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- Non Browser Process Beaconing to External Host at a Regular Interval
- Chrome Secure Preferences File Rewritten by a Non Browser Process
- LONGTALE Chrome Extension Identifier Written to a Browser Profile
- Scheduled Task Registered Under a Known Malicious Task Name
- Windows Installer Executing a Package With a Non Installer Extension
- Web Browser Spawning Script Interpreter
- Known Sideloading Target Library Loaded From a User Writable Directory
- Curl Download And Execute Combination
- Outbound Request to a Character Transposition Typosquat of a Known Media or Nonprofit Domain