Two separate Chinese-linked threat groups exploited an identical Chrome and Windows zero-day chain against NGOs before Google released a patch, according to a new report from Volexity.

The security firm disclosed that two independent espionage campaigns both converged on the same vulnerability chain, with spear-phishing activity detected as early as September 1, 2026. By the time Google shipped a fix days later, both groups had already established footholds in targeted organizations.

What makes this discovery unusual is that two unconnected state-sponsored actors independently found and weaponized the same zero-day exploit chain before it was publicly known. Threat intelligence analysts consider such convergence rare, signaling that capable adversaries are actively hunting the same high-value unpatched flaws in parallel.

The attack itself chained a Chrome sandbox escape with a Windows privilege escalation vulnerability — a cross-vendor combination that exploits the gap between separate patch cycles. By compromising both a browser flaw and an operating system flaw, the attackers achieved full system control. Volexity noted that while both groups used the same entry method and privilege escalation path, each deployed its own distinct backdoor after gaining access, confirming the campaigns operated independently.

The timeline is critical: both operations ran for more than a week before Google's patch arrived. Any NGO using unpatched Chrome during that window faced exposure to nation-state compromise — with no vendor-supplied fix available as a defense.

Civil society organizations remain frequent targets for state-sponsored espionage because of their access to sensitive advocacy networks and policy discussions. Yet NGOs typically lack the security staffing, threat intelligence partnerships, and budgets that enterprises deploy against such sophisticated attacks. Timely vendor patching often represents their only realistic protection against this class of threat.

Organizations should ensure all Chrome installations are fully updated and review the indicators of compromise published in Volexity's report, which enable defenders to hunt for the command-and-control domains and file hashes tied to both campaigns.

The parallel exploitation underscores an intensifying race between attackers and defenders. When multiple independent groups find the same zero-day before vendors ship fixes, the cost of slow patching becomes measured in nation-state intrusions against organizations least equipped to recover from them.


根據Volexity一份新報告,兩個獨立的中國關聯威脅組織在Google發布補丁前,利用完全相同的Chrome及Windows零日漏洞鏈攻擊了非政府組織(NGOs)。

該網絡安全公司透露,兩個獨立的間諜行動均匯聚於同一漏洞利用鏈,最早於2026年9月1日偵測到魚叉式釣魚活動。當Google數日後發布修復程式時,兩個組織已在目標組織中建立了據點。

此發現之所以非同尋常,在於兩個互不關聯的國家資助行為者,在漏洞公開前,各自獨立發現並武器化了同一零日漏洞利用鏈。威脅情報分析師認為,這種匯聚現象相當罕見,表明能力卓越的攻擊者正同步積極搜尋相同的高價值未修補漏洞。

該攻擊本身將Chrome沙盒逃逸漏洞與Windows權限提升漏洞串聯——這是一種跨供應商的組合利用,專門利用不同補丁週期之間的間隙。通過同時入侵瀏覽器缺陷與作業系統缺陷,攻擊者取得了完整的系統控制權。Volexity指出,儘管兩個組織使用相同的入侵途徑與權限提升路徑,但各自在取得存取權限後部署了獨特的後門程式,證實了這兩個行動係獨立運作。

時間線至關重要:在Google補丁發布前,兩個行動均已運行超過一週。在此期間,任何使用未修補版Chrome的NGO均面臨國家級入侵的風險——而當時並無供應商提供的修復措施可供防禦。

民間社會組織因能接觸敏感倡議網絡及政策討論,仍經常成為國家資助間諜活動的目標。然而,NGO通常缺乏企業用以應對此類精密攻擊的安全團隊、威脅情報合作夥伴及預算。及時的供應商補丁往往是其對抗此類威脅的唯一實際防護。

各組織應確保所有Chrome安裝已完全更新,並查閱Volexity報告中公佈的入侵指標,使防禦者能搜尋與兩個行動相關的指揮控制域名及檔案雜湊值。

這次同步利用行動突顯了攻擊者與防禦者之間日益激烈的競賽。當多個獨立組織在供應商發布修復程式前發現相同的零日漏洞時,緩慢補丁所付出的代價,便以針對最無力恢復的組織所進行的國家級入侵來衡量了。

新聞來源 / Original News Source