Earlier this month, staff at several non-profits received an email asking them to click a link to a real U.S. university website. Anyone who hovered over it saw a recognized .edu domain. One click later, with no attachment to open and nothing to install, their fully updated Chrome browser handed a China-linked group control of the machine. Here is why the usual safety checks failed, and what a firm with no security team can do about it.

Why the usual checks failed

Two habits most firms rely on did not help here. The first is "hover before you click." The link genuinely pointed at the university. The attackers abused a flaw on the university's own site to bounce visitors onward after the click, so the destination looked safe right up until it wasn't.

The second is "keep the browser updated." The three flaws in the chain had already been fixed in Chrome's open-source code, but the fixes had not yet shipped in a stable release. A browser reporting itself fully up to date was still exploitable. Security researchers call that a patch gap, and it turned known bugs into working zero-days for everyone running Chrome on Windows. If your assurance reporting says "100 percent of endpoints on the latest browser version," that metric protected no one in this campaign.

The exploit page was also picky. It served the attack only to Chrome on Windows and showed nothing to anyone else, which is why a quick test from a phone or a Mac would have found the link harmless.

What the attacker actually gets

The group Volexity tracks as UTA0560 installed a small backdoor called GRIMWEDGE. It runs in memory, polls a command server, and does a handful of things well: list folders and running programs, read files, run commands in a hidden window, and upload whatever it fetches. It has no built-in persistence and no ransomware component. Nothing encrypts, nothing breaks, and your staff notice nothing.

That quietness is the point, and it is what makes the aftermath expensive. The backdoor leaves little on disk, so the evidence your investigator would normally rely on may not survive a reboot. When a regulator, insurer, or grant funder asks which files left the building and when, that becomes a hard question to answer, and the burden of answering it is yours.

A second China-linked group, APT31, ran the same exploit chain in the same window with a different goal. Its payload was a malicious Chrome extension posing as a Google Gemini add-on that logs keystrokes, captures screenshots, and steals session cookies. Stolen cookies matter more than stolen passwords: a valid session token walks past the multi-factor prompt and opens webmail and cloud apps as the user, with no password-reset event to tip anyone off.

The targets were non-governmental organizations, but nothing in the tooling is specific to them. A law firm's client correspondence, a practice's patient records, or an accountant's client files sit behind exactly the same browser.

The practical takeaway

Five things, in order. None of them need a security team.

  1. Force Chrome to relaunch, then confirm it. Chrome downloads updates in the background but only applies them when the browser restarts, so a laptop that has been open for two weeks is running the old version no matter what your inventory says. Type chrome://version on a few machines and check. Do the same for Edge, which shares the same engine.
  2. Apply this month's Windows updates on the same pass. The last step of the chain is a Windows flaw, and a machine with a patched browser and an unpatched Windows still gives the attacker most of what they came for.
  3. Block the domain ocr.opusaccel[.]top at your DNS filter, and have whoever manages your firewall search back to late August for any lookups of it.
  4. Pull a list of installed Chrome extensions across the firm and look for one with the ID ckiknalbeplpcpofpnabcnhjcegckfei. It calls itself a Gemini extension. It is not.
  5. If you find any of that, do not reboot the machine. The backdoor lives in memory, and a restart destroys the best evidence you have. Unplug it from the network and call your incident response contact.

One last point for the firms that answer to an auditor or a funder. Notification obligations follow the data, not the size of the intrusion. Personal data on clients, patients, or donors touched by a file-read-and-upload sequence commonly puts you into breach-notification territory, and grant agreements typically carry reporting deadlines shorter than the statutory ones. Knowing what you would be able to prove, before something like this happens, is worth an afternoon.

The full technical breakdown, including the indicators your IT provider should be hunting for, is in our Threat Intelligence Center write-up. If you are not sure whether your browsers actually restart when they update, a security assessment will tell you.