JungleBamboo is a China-linked cyber-espionage threat actor also tracked as APT31, Violet Typhoon, and TA412. In 2026, it conducted targeted phishing operations using a shared Chrome-and-Windows exploitation chain to compromise selected victims. The chain exploited browser and Windows vulnerabilities to escape browser security boundaries and inject code into Chrome processes. JungleBamboo used distinct infrastructure and post-exploitation tooling from other actors observed using the same exploit code. JungleBamboo deployed the SUPERSTOMP loader to silently install LONGTALE, also known as GemStone, a malicious Chrome extension masquerading as a Google Gemini-related extension. SUPERSTOMP altered Chrome preference-integrity protections to enable extension installation. LONGTALE supported credential and form-data collection, theft of cookies and web-session tokens, keylogging, clipboard and browser-data collection, keyword-triggered screenshot capture, periodic data exfiltration, and remotely directed collection and surveillance functions. The actor’s activity is consistent with intelligence collection against nongovernmental, government, and public-policy targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Trois vulnérabilités critiques ont été enchaînées : CVE-2026-85046 : Type Confusion dans le moteur JavaScript V8 de Chrome.
CVE-2026-85880 : Élévation de privilèges noyau Windows via RtlpCreateServerAcl.
CVE-2026-87491 : Échappement de sandbox WebAssembly dans Chrome V8.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Groupe d’espionnage attribué à la Chine, associé à l’exploitation de zero-days Chrome et Windows contre des gouvernements, ONG et organisations de politique publique. Il a utilisé LONGTALE, une extension Chrome se faisant passer pour Google Gemini, pour dérober identifiants, cookies et sessions.
Conducted targeted spear-phishing campaigns against NGOs, using a chained Chrome and Windows exploit sequence to escape security boundaries and delivering SUPERSTOMP to install the LONGTALE credential-stealing Chrome extension.
Used the same Chrome/Windows exploit chain as UTA0560 against separate targets, deploying the SUPERSTOMP loader and LONGTALE malicious Chrome extension to capture credentials, cookies, session tokens, keystrokes, and screenshots.
Using the same Chrome-Windows exploit chain to deploy SUPERSTOMP and LONGTALE/GemStone, a malicious Chrome extension masquerading as Google Gemini that steals credentials, cookies, sessions, browser data, screenshots, and keystrokes for surveillance and credential theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.