UTA0560 is a China-linked cyber-espionage threat cluster observed targeting nongovernmental organizations, including through donation- and financial-themed spear-phishing lures. Activity observed in 2026 used reflected cross-site-scripting flaws on legitimate university websites to redirect selected Chrome-on-Windows victims to the BlueMoon exploit chain. The chain exploited vulnerabilities in Chrome V8 and WebAssembly and a Windows kernel privilege-escalation flaw, allowing escape from browser security boundaries, code injection into Chrome, and delivery of follow-on payloads. UTA0560 deployed GRIMWEDGE, an in-memory JScript backdoor, following exploitation. GRIMWEDGE supports host reconnaissance, file and directory operations, process enumeration and termination, hidden command execution, staged payload retrieval, and file upload. The actor used DLL sideloading to launch its malware and established scheduled-task persistence in observed intrusions. UTA0560 used the same core exploit shellcode as the separate China-linked JungleBamboo/APT31 cluster, while maintaining separate infrastructure and delivering distinct post-exploitation malware. The shared exploit chain indicates common access to exploitation tooling but does not establish that JungleBamboo is an alias or subgroup of UTA0560.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Trois vulnérabilités critiques ont été enchaînées : CVE-2026-85046 : Type Confusion dans le moteur JavaScript V8 de Chrome.
CVE-2026-85880 : Élévation de privilèges noyau Windows via RtlpCreateServerAcl.
CVE-2026-87491 : Échappement de sandbox WebAssembly dans Chrome V8.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Groupe attribué à la Chine menant une campagne d’espionnage contre des organismes gouvernementaux, ONG et organisations de politique publique en Asie et en Amérique du Nord. Il a déployé la backdoor CLEANGULP après exploitation d’une chaîne de vulnérabilités Chrome et Windows.
Conducted targeted spear-phishing campaigns against NGOs, exploiting a chained Chrome and Windows vulnerability sequence to escape browser and OS security boundaries and deploy the GRIMWEDGE JScript backdoor.
Conducted a spear-phishing espionage campaign against NGOs using a shared Chrome and Windows exploit chain, then deployed the in-memory GRIMWEDGE JScript backdoor for reconnaissance, file and process management, command execution, and payload delivery.
Conducting espionage-oriented spear-phishing against NGOs, exploiting a Chrome and Windows zero-day/N-day chain to establish an initial foothold with the GRIMWEDGE JavaScript backdoor for reconnaissance, file and process management, command execution, file retrieval, and additional payload delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.