SECURITY·중요도 8·2026. 09. 15.·The Hacker News
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
── KO ──────────────────
중국 해킹 팀이 Chrome와 Windows의 제로데이 취약점을 이용해 GRIMWEDGE를 배포했습니다.
중국 해킹 그룹이 최근 패치된 Google Chrome과 Microsoft Windows의 보안 취약점을 악용하여 악성 자바스크립트 백도어인 GRIMWEDGE를 배포하는 피싱 캠페인을 전개했습니다. 이 활동은 다수의 비정부기구(NGO)를 목표로 하였으며, Volexity는 이를 UTA0560이라는 이름으로 추적하고 있습니다. 이번 사건은 2026년 9월 1일에 발생했습니다.
── EN ──────────────────
Chinese hackers exploit Chrome and Windows zero-day flaws to deploy GRIMWEDGE.
A Chinese hacking group has been linked to a spear-phishing campaign that exploits recently patched security vulnerabilities in Google Chrome and Microsoft Windows to deploy a malicious JavaScript backdoor known as GRIMWEDGE. The activity targeted multiple non-governmental organizations (NGOs) and was tracked by Volexity under the moniker UTA0560. This incident occurred on September 1, 2026.