A Chinese threat actor, identified by the codename UTA0565, has recently been observed leveraging a newly disclosed exploit chain affecting Google Chrome and Microsoft Windows. This operation, characterized by the use of zero-day vulnerabilities, was executed through a series of deceptive websites.
Details of the Exploit
The attacks, which were detected on September 3 and 4, 2026, involved the exploitation of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) alongside a vulnerability impacting Windows Advanced Local Procedure Call (CVE-2026-85880). By chaining these vulnerabilities, the threat actor was able to escape the browser’s sandbox environment, ultimately achieving remote code execution.
According to Volexity researchers Damien Cash and Tom Lancaster, UTA0565 employed a variety of disguises, impersonating entities such as media organizations and non-governmental organizations (NGOs). Their analysis highlights a significant departure from previous attack strategies, as this campaign utilized multiple fake websites to mislead victims.
Targeted Campaigns
One notable campaign focused on Asian government entities, disseminating phishing emails in both Chinese and English. These emails urged recipients to support Hong Kong activist Chow Hang-tung, while masquerading as communications from the Center for American Progress (CAP). It is worth noting that Chow was sentenced to over seven years in prison earlier this month.
The phishing messages contained spoofed links directing users to “chinadigitaltimes[.]top” and “americanprgoress[.]top,” which closely mimicked the appearance of China Digital Times and CAP. These sites were designed to load an additional HTML element via a hidden iframe.
Payload and Capabilities
The HTML element, referred to as “config.html,” utilized the BlueMoon exploit kit, combining the aforementioned vulnerabilities to deliver a final payload. This payload, named “chrome_cleanup.exe,” was downloaded from the fraudulent domain and belongs to a malware family known as CLEANGULP. This malware is compiled using the Microsoft Visual C Compiler and offers a range of capabilities:
- shell: Executes commands
- ps: Lists running processes
- upload: Uploads files
- download: Downloads files
- bof: Executes a Beacon Object File (BOF)
Interestingly, CLEANGULP has been observed using a hard-coded domain, “thecovnresation[.]com,” for command-and-control (C2) communications over HTTP. This domain appears to mimic “theconversation[.]com,” a reputable non-profit media outlet known for its academic research and commentary.
Broader Implications
Volexity suggests that the widespread adoption of this exploit across various threat actors indicates a coordinated effort within the Chinese cyber espionage community. The core exploit kit appears to have been shared, customized, and weaponized by multiple groups. The activity documented thus far reflects only the observations of two organizations, implying that the full scope and impact of these attacks may be significantly broader.
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor, identified by the codename UTA0565, has recently been observed leveraging a newly disclosed exploit chain affecting Google Chrome and Microsoft Windows. This operation, characterized by the use of zero-day vulnerabilities, was executed through a series of deceptive websites.
Details of the Exploit
The attacks, which were detected on September 3 and 4, 2026, involved the exploitation of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) alongside a vulnerability impacting Windows Advanced Local Procedure Call (CVE-2026-85880). By chaining these vulnerabilities, the threat actor was able to escape the browser’s sandbox environment, ultimately achieving remote code execution.
According to Volexity researchers Damien Cash and Tom Lancaster, UTA0565 employed a variety of disguises, impersonating entities such as media organizations and non-governmental organizations (NGOs). Their analysis highlights a significant departure from previous attack strategies, as this campaign utilized multiple fake websites to mislead victims.
Targeted Campaigns
One notable campaign focused on Asian government entities, disseminating phishing emails in both Chinese and English. These emails urged recipients to support Hong Kong activist Chow Hang-tung, while masquerading as communications from the Center for American Progress (CAP). It is worth noting that Chow was sentenced to over seven years in prison earlier this month.
The phishing messages contained spoofed links directing users to “chinadigitaltimes[.]top” and “americanprgoress[.]top,” which closely mimicked the appearance of China Digital Times and CAP. These sites were designed to load an additional HTML element via a hidden iframe.
Payload and Capabilities
The HTML element, referred to as “config.html,” utilized the BlueMoon exploit kit, combining the aforementioned vulnerabilities to deliver a final payload. This payload, named “chrome_cleanup.exe,” was downloaded from the fraudulent domain and belongs to a malware family known as CLEANGULP. This malware is compiled using the Microsoft Visual C Compiler and offers a range of capabilities:
Interestingly, CLEANGULP has been observed using a hard-coded domain, “thecovnresation[.]com,” for command-and-control (C2) communications over HTTP. This domain appears to mimic “theconversation[.]com,” a reputable non-profit media outlet known for its academic research and commentary.
Broader Implications
Volexity suggests that the widespread adoption of this exploit across various threat actors indicates a coordinated effort within the Chinese cyber espionage community. The core exploit kit appears to have been shared, customized, and weaponized by multiple groups. The activity documented thus far reflects only the observations of two organizations, implying that the full scope and impact of these attacks may be significantly broader.