GRIMWEDGE JavaScript backdoor with persistent C2 polling
Malware Activity
Summary
Hide ▲
Show ▼
The GRIMWEDGE JavaScript backdoor is being deployed with a persistent C2 loop, giving operators host reconnaissance, file and process management, command execution, and payload delivery on compromised systems. It polls ocr.opusaccel[.]top for instructions and executes them in memory via eval(). The activity increases the risk of follow-on tooling and deeper hands-on-keyboard abuse after the initial foothold.
Related Happenings
ErrTraffic and Cruciferra ClickFix BYOVD malware activity
Malware Activity
H score72
First: 20.08.2026 20:23
Last: 20.08.2026 20:23
Sources 1
About this happening:
The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes....
ErrTraffic and Cruciferra ClickFix BYOVD malware activity
Malware ActivityAbout this happening: The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes....
Google DeepMind launches Gemini 3.5 Flash Cyber via CodeMender for vulnerability discovery and patching
Security Tool/Service
H score26
First: 21.07.2026 18:09
Last: 21.07.2026 18:09
Sources 1
About this happening:
Google DeepMind released Gemini 3.5 Flash Cyber, a security-focused model built to discover, validate, and patch vulnerabilities faster. The capability is being delive...
Google DeepMind launches Gemini 3.5 Flash Cyber via CodeMender for vulnerability discovery and patching
Security Tool/ServiceAbout this happening: Google DeepMind released Gemini 3.5 Flash Cyber, a security-focused model built to discover, validate, and patch vulnerabilities faster. The capability is being delive...
ClickLock ClickFix macOS targeting campaign
Campaign
H score33
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
ClickLock ClickFix macOS targeting campaign
CampaignAbout this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
DEEP#DOOR Python backdoor framework
Malware Activity
H score28
First: 30.04.2026 15:36
Last: 30.04.2026 15:36
Sources 1
About this happening:
DEEP#DOOR is a newly disclosed Python-based backdoor framework that can keep persistent access to compromised Windows hosts while stealing browser, SSH, and cloud cred...
DEEP#DOOR Python backdoor framework
Malware ActivityAbout this happening: DEEP#DOOR is a newly disclosed Python-based backdoor framework that can keep persistent access to compromised Windows hosts while stealing browser, SSH, and cloud cred...
Transparent Tribe AI-assisted implant campaign targeting India
Campaign
H score32
First: 06.03.2026 17:11
Last: 06.03.2026 17:11
Sources 1
About this happening:
Transparent Tribe (APT36) is running an evolving campaign that now includes PATCHCORD and SHEETCORD alongside earlier AI-assisted implants. The newer activity targ...
Transparent Tribe AI-assisted implant campaign targeting India
CampaignAbout this happening: Transparent Tribe (APT36) is running an evolving campaign that now includes PATCHCORD and SHEETCORD alongside earlier AI-assisted implants. The newer activity targ...
Latest development: 13.08.2026 18:00
Transparent Tribe, assessed with moderate confidence as APT36, is targeting Afghan telecom providers, Indian government IT networks, and South Asian critical infrastructure with PATCHCORD and SHEETCORD. The implants are delivered through fake Afghan Telecom lures, Telecom_TMS.zip, and nic-support[.]site, then use browser-shortcut hijacking or the Windows Startup folder for persistence, Google Sheets or GitHub Gists for C2, and infrastructure tied to CVE-2024-6387 exploit material.
Timeline
-
15.09.2026 08:31 1 articles · 2h ago
Spear-phishing campaign deploys GRIMWEDGE against multiple NGOs
Campaign Scope UpdateA Chinese threat actor targeted multiple non-governmental organizations with spear-phishing emails that used a reflected XSS redirect from a U.S.-based university website into a multi-stage Chrome-Windows exploit chain, delivering the GRIMWEDGE JavaScript backdoor on September 1, 2026.
Show sources
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE — thehackernews.com — 15.09.2026 08:31
-
15.09.2026 08:31 2 articles · 2h ago
GRIMWEDGE polls ocr.opusaccel[.]top for in-memory commands
Technical Analysis UpdateGRIMWEDGE enters a persistent command loop that polls ocr.opusaccel[.]top, receives instructions, and executes them in memory via eval(); the backdoor supports host reconnaissance, file and process management, directory operations, command execution, and payload delivery on compromised Windows hosts.
Show sources
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE — thehackernews.com — 15.09.2026 08:31
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE — thehackernews.com — 15.09.2026 08:31