JungleBamboo, also known as APT31, Violet Typhoon, and TA412, is a China-linked threat cluster. In September 2026, it conducted spear-phishing operations using a Chrome-and-Windows exploit chain shared byte-for-byte with UTA0560, while maintaining separate delivery infrastructure and distinct post-exploitation tooling. The chain exploited CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escape browser security boundaries, elevate privileges, inject code into a Chrome process, and deliver a final payload. JungleBamboo deployed the SUPERSTOMP loader to tamper with Chrome Secure Preferences and silently install LONGTALE, a malicious browser extension masquerading as a Google Gemini extension. LONGTALE harvested keystrokes, form data, clipboard contents, browser cookies, local and session storage, and browsing data; it also captured keyword-triggered screenshots and supported remotely configured surveillance and collection functions. The operation used phishing links, browser and operating-system targeting checks, and browser-extension abuse to establish access and collect victim data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE-2026-85046 : type confusion dans le moteur V8 JavaScript de Chrome, permettant une lecture/écriture arbitraire dans le sandbox V8. La vulnérabilité avait été signalée au projet Chromium le 4 août 2026 et corrigée dans le code source open-source, mais aucun patch n’avait été publié pour Google Chrome au moment de l’attaque.
CVE-2026-85880 : vulnérabilité dans RtlpCreateServerAcl du noyau Windows, permettant une élévation de privilèges locale et l’échappement du renderer sandboxé de Chrome.
CVE-2026-87491 : défaut WebAssembly permettant l’échappement du sandbox V8.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.