← All briefs
critical October 1, 2026

Patch Gap Zero Day Chain: Three Chinese Actors Share a Chrome and Windows Kernel Exploit Kit

Source report →

A spear-phishing campaign detected on September 1, 2026 led to the discovery of a three-stage exploit chain targeting Google Chrome and the Windows kernel. The first Chrome flaw had already been fixed in Chromium source code but had not yet reached a stable Chrome release, creating a window in which the vulnerability was effectively a zero-day for Chrome users while the patch was publicly visible. Investigators assessed with medium confidence that the exploit developer identified the flaw by reverse-engineering that public fix.

The chain begins with a V8 type confusion that provides arbitrary read and write inside the V8 sandbox, followed by a WebAssembly flaw used to escape it and a previously unknown Windows kernel vulnerability used to escape the Chrome renderer sandbox and inject into the browser process. Delivery uses a lure page, an obfuscated JavaScript loader that checks for Chrome on Windows, and a hidden exploit page containing Base64-encoded shellcode for host reconnaissance, kernel privilege escalation, and browser-process injection. The exploit includes retry logic, environment checks, development parameters, and a configurable payload URL, allowing the same core exploit to deliver different malware.

The actors diverged after gaining execution inside the Chrome browser process. One deployed a DLL side-loading chain with scheduled-task persistence, then delivered an MSI-based JScript backdoor that operated in memory and supported reconnaissance, file operations, process control, uploads, and arbitrary execution. A second actor installed the LONGTALE Chrome extension, masquerading as a Google Gemini add-on, to capture keystrokes, form data, cookies, browser storage, and targeted screenshots. LONGTALE had no command-execution capability and instead functioned as a credential and session harvester. The LONGTALE installer bypassed Chrome's extension integrity protections by modifying the profile's `Secure Preferences` file, removing newer encrypted integrity values, inserting the malicious extension, and generating valid legacy authentication codes. Chrome then accepted the forged state and re-signed it under the newer integrity scheme. The actor also hid its command-and-control infrastructure behind Cloudflare Tunnels.

A third actor used the same exploit kit two days later through typosquatted websites that mirrored legitimate content while loading the exploit in a hidden iframe. Its reconnaissance and privilege-escalation stages matched the earlier activity, but the final stage downloaded and launched the implant in-process through the Windows shell rather than using `cmd.exe` and a transfer utility. The implant established scheduled-task persistence and supported command execution, process discovery, file transfer, and beacon object file execution. Additional observations by other vendors indicate that the exploit kit was shared and customized across multiple threat groups rather than being exclusive to a single actor.

SHA256 FILE HASH 14
7a52ff23949edee8faa61ce0def6dbca8b7e5943c54d23376cc190762ea3985c
cd0c21f9b32b7feeda1787fccab622dec60ecdf84c0538c08bde3946856b0fa0
b7b0cd6539464ab39c6526e499f86d611faa21c5af945535ebaf187cec543af1
5995f42a828606705a7339d58a665c229936e81c4e539cdfa115eb46a2eb53d6
51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863cc
d17053557bb90298f7b115432b4820a248fdbe678bca31721529b1f51a82343b
337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d
69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc
3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f
56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951
59dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcb
e2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c0
5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3
8858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cb
SHA1 FILE HASH 1
668aa5551315ab26b67118fbb29f8e4560a1e1af
MD5 FILE HASH 1
177652713dad3c128bd9195abf2b7603
DOMAIN 14
cloud.shinewrist[.]net
ocr[.]opusaccel[.]top
gitprogram[.]com
msbenefit[.]com
document.gitprogram[.]com
americanprgoress[.]top
chinadigitaltimes[.]top
thecovnresation[.]com
thecovnresation[.]net
personclouds[.]com
borneobulletins[.]top
outsourcingwise[.]net
halal-navi[.]net
halaltak[.]net
IP ADDRESS 2
206.166.251[.]164
96.9.125[.]52
EMAIL 1
ircribbin77@hotmail[.]com
URL 5
https://photos.msbenefit[.]com/fa/t3
https://photos.msbenefit[.]com/fb/w3z
https://proof.gitprogram[.]com/a4/j8
https://xyz0102.gitprogram[.]com/a001
https://americanprgoress[.]top/chrome_cleanup.exe

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Non Browser Process Beaconing to External Host at a Regular Interval
  • Chrome Secure Preferences File Rewritten by a Non Browser Process
  • LONGTALE Chrome Extension Identifier Written to a Browser Profile
  • Scheduled Task Registered Under a Known Malicious Task Name
  • Windows Installer Executing a Package With a Non Installer Extension
  • Web Browser Spawning Script Interpreter
  • Known Sideloading Target Library Loaded From a User Writable Directory
  • Curl Download And Execute Combination
  • Outbound Request to a Character Transposition Typosquat of a Known Media or Nonprofit Domain