A Chinese threat actor, codenamed UTA0565, has been detected exploiting a recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, identified on September 3 and 4, 2026, involved chaining two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to bypass the browser's sandbox and achieve remote code execution. Researchers at Volexity, Damien Cash and Tom Lancaster, revealed that a threat actor masqueraded as various entities, including media organizations and a non-governmental organization (NGO).

This actor's campaigns were distinct from previous attacks by employing multiple fake websites to deceive victims. A targeted campaign exploited vulnerabilities in Asian government systems with Chinese- and English-language phishing emails.

The emails urged recipients to support Hong Kong activist Chow Hang-tung, masquerading as the Center for American Progress (CAP). Chow had been sentenced to seven years and three months earlier this month. The emails contained spoofed links to "chinadigitaltimes[.

]top" and "americanprgoress[. ]top," which replicated the appearance of China Digital Times and CAP, while loading an additional HTML element via a hidden iframe. The HTML element "config.html" is linked to the BlueMoon exploit kit, which includes the BlueMoon, BlueMoon2, and BlueMoon3 components. The final "pp" shellcode downloads a file named "chrome_cleanup.exe" from a fake domain.

The malware family, dubbed CLEANGULP, is built with the Microsoft Visual C Compiler and supports the following functions: - Shell, to run a command - Ps, to list running processes - Upload, to upload a file - Download, to download a file - BoF, to execute a beacon object file (BOF) This malware has been detected to use a hard-coded domain named "thecovnresolution[. ]com" for command-and-control (C2) over HTTP, mimicking a non-profit media outlet called "theconversation[.]com."