Researchers have tied a China-linked cluster tracked as APT31, JungleBamboo and UTA0560 to an exploit chain spanning Google Chrome and Microsoft Windows, using CVE-2026-85046, CVE-2026-85880 and CVE-2026-87491 to deploy the GRIMWEDGE implant. Additional tooling associated with the activity includes BlueMoon, GemStone, LONGTALE and SUPERSTOMP, along with the artifacts msgbox.exe and wsc.dll.