THREAT OPS › Threat News › Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
<p><!-- START MG ACF TO CONTENT --></p> <div style="display: none;"> <section class="mgpb-hero mgpb-hero--detail mgpb-hero--black mgpb-hero--background-image mgpb-hero--image"> <div class="mgpb-hero__image mgpb-hero__image--background"> <img alt="" class="attachment-16-9-large size-16-9-large" height="1080" src="https://www.volexity.com/wp-content/uploads/2026/09/Volexity-Blog-Mind-the-Patch-Ga
Attributed threat actors
- ZIRCONIUMG0128
MITRE ATT&CK techniques
Indicators of compromise
- d17053557bb90298f7b115432b4820a248fdbe678bca31721529b1f51a82343bsha256
- 337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130dsha256
- 7a52ff23949edee8faa61ce0def6dbca8b7e5943c54d23376cc190762ea3985csha256
- cd0c21f9b32b7feeda1787fccab622dec60ecdf84c0538c08bde3946856b0fa0sha256
- b7b0cd6539464ab39c6526e499f86d611faa21c5af945535ebaf187cec543af1sha256
- 5995f42a828606705a7339d58a665c229936e81c4e539cdfa115eb46a2eb53d6sha256
- 51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863ccsha256
- 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dcsha256
- 3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367fsha256
- 56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951sha256
- 59dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcbsha256
- e2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c0sha256
- 5eb5645511b00e4f4d73125654eeb3a3930fcf09c65685dc7f03f725331492e3sha256
- 814fa9c2b75f95b8140ea6d460877772a2d4d507sha1
- CVE-2026-85046cve
- CVE-2026-87491cve
- CVE-2026-85880cve
- https://cloud.shinewrist.net/<removed>/Files1.htmlurl
- https://cloud.shinewrist.net/url
- https://cloud.shinewrist.net/<removed>/page.html?mode=payloadurl
- https://cloud.shinewrist.net/<removed>/page.html?mode=payload&exeurl=http://cloud.shinewrist.net/<removed>/msgbox.exeurl
- https://cloud.shinewrist.net/<removed>/msgbox.exeurl
- https://cloud.shinewrist.net/<removed>/%COMPUTERNAME%.txturl
- https://ocr.opusaccel.topurl
- https://photos.msbenefit.com/fb/w3zurl
- https://proof.gitprogram.com/a4/j8url
- https://xyz0102.gitprogram.com/a001url
- https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploiturl
- https://photos.msbenefit.com/fa/t3url
- 206.166.251.164ipv4
- document.gitprogram.comdomain
- d71bedcf-307a-4432-beec-ce943223d0e3.cfargotunnel.comdomain
- hotmail.comdomain