VMTech
Discuss a project

UTA0565 Uses Chrome and Windows Zero-Days to Deliver CLEANGULP

UTA0565 Uses Chrome and Windows Zero-Days to Deliver CLEANGULP

Chinese threat actor UTA0565 exploited a chain of three zero-day vulnerabilities in Google Chrome and Microsoft Windows to deploy the CLEANGULP malware family through fraudulent websites. Volexity detected the activity on September 3 and 4, 2026. The chain combined Chrome flaws CVE-2026-85046 and CVE-2026-87491 with CVE-2026-85880, a vulnerability in Windows Advanced Local Procedure Call (ALPC).

The exploit sequence enabled attackers to break out of Chrome's browser sandbox and achieve remote code execution. Volexity attributed the campaigns to UTA0565 and said the actor impersonated several types of organization, including media outlets and a non-governmental organization.

Phishing lures led victims to impersonated websites

One campaign targeted Asian government entities using phishing emails in Chinese and English. The messages asked recipients to support Hong Kong activist Chow Hang-tung and posed as communications from the Center for American Progress. Chow was sentenced to seven years and three months in prison earlier in September.

Spoofed links directed recipients to chinadigitaltimes[.]top and americanprgoress[.]top. Those domains imitated China Digital Times and the Center for American Progress. The pages loaded an additional HTML element, config.html, in a hidden iframe.

That element used the BlueMoon exploit kit to combine all three vulnerabilities. Its final pp shellcode downloaded an executable named chrome_cleanup.exe from the fraudulent domain. The downloaded program was identified as CLEANGULP and was built with the Microsoft Visual C Compiler.

CLEANGULP supports command and file operations

CLEANGULP can run shell commands, list active processes, upload and download files, and execute a beacon object file (BOF). Volexity also found a hard-coded HTTP command-and-control domain, thecovnresation[.]com, which appears intended to resemble the non-profit media outlet The Conversation.

Volexity said the apparent use of the core kit by multiple threat actors may indicate coordinated activity within the Chinese CNE community, with the kit shared, modified and weaponized by different groups. The researchers cautioned that observations from two organizations may represent only part of the overall activity and impact.

What organizations should take from the campaign

The case ties browser security directly to email and web impersonation risk: a phishing message can guide a target to a convincing site, while a chained browser and operating-system exploit can convert that visit into code execution. Businesses should apply available Chrome and Windows security updates promptly and ensure that phishing defenses and investigations account for lookalike domains, hidden page elements and suspicious browser downloads.

#cybersecurity#zeroday#phishing#chromesecurity
Open analytics
On the site 0 views
min read 3 23.09.2026
Instagram

UTA0565 Uses Chrome and Windows Zero-Days to Deliver CLEANGULP

Open the post on Instagram ↗