Chinese State-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A suspected Chinese threat group tracked as UTA0565 chained three zero-day vulnerabilities in Google Chrome and Microsoft Windows to compromise Asian government entities. The attacks used fake NGO websites to bypass browser sandboxes and install a previously undocumented backdoor.
- Threat Intelligence Researchers
- Focus on the attribution, malware reverse-engineering, and the implications of shared exploit frameworks among APTs.
- Enterprise Security Defenders
- Focus on the operational risk of patch gaps and the necessity of rapid browser update enforcement.
Perspectives this story doesn't cover
- Targeted Asian Government Entities
- Google and Microsoft Security Teams
Why it matters
This campaign demonstrates that top-tier zero-day exploits are being rapidly shared across multiple Chinese state-aligned hacking groups. For network defenders, it highlights the critical risk of 'patch gap' vulnerabilities where exploits are weaponized before vendor updates can be widely deployed.
A suspected Chinese state-aligned threat group tracked as UTA0565 successfully chained three zero-day vulnerabilities across Google Chrome and Microsoft Windows to breach Asian government networks earlier this month. The attackers bypassed browser security boundaries entirely, using fake non-governmental organization websites to silently install a newly discovered backdoor named CLEANGULP.[1][2]
The exploit sequence functioned like a set of nested keys. When a target visited a malicious site, a hidden iframe triggered a Chrome V8 type-confusion flaw, designated CVE-2026-85046, to execute code within the browser's renderer. A second Chrome vulnerability, CVE-2026-87491, then allowed the attackers to escape the browser sandbox. Finally, the chain abused a Windows Advanced Local Procedure Call defect, CVE-2026-85880, to escalate privileges to the system level.[1][3]
This zero-click infection chain required no user interaction beyond visiting the compromised page. The attacks occurred on September 3 and 4, 2026, while the vulnerabilities remained unpatched in Google Chrome's stable release channel. Because the initial Chrome flaw was patched in the Chromium open-source code repository before the update reached end users, attackers were able to reverse-engineer the fix and weaponize it against organizations that had not yet received the update.[1][2]
Rather than relying on malicious email attachments, UTA0565 lured victims to highly convincing typosquatted domains. The group sent Chinese- and English-language spear-phishing emails urging recipients to support imprisoned Hong Kong activist Chow Hang-tung, who was sentenced to over seven years in prison earlier this year.[1][2]
Rather than relying on malicious email attachments, UTA0565 lured victims to highly convincing typosquatted domains.
The emails directed targets to fake websites impersonating legitimate organizations, including the Center for American Progress and China Digital Times. Because the sites loaded genuine content from the real organizations while concealing the exploit code in an invisible iframe, the operation evaded immediate suspicion from the targeted policy analysts and government officials.[1][2]
Once the exploit chain secured system-level access, it deployed CLEANGULP, a previously undocumented malware family written in C and compiled with Microsoft Visual C++. The implant is heavily obfuscated through control-flow flattening and indirect calls, and it establishes persistence by creating a scheduled Windows task named MicrosoftIME.[1][3]
CLEANGULP provides operators with a flexible post-compromise platform capable of executing shell commands, enumerating processes, and transferring files. It communicates with command-and-control servers using AES-256-GCM encryption, connecting to hardcoded typosquatted domains such as 'thecovnresation[.]com', which mimics the academic media network The Conversation.[1]
The most significant aspect of the campaign is the tooling itself. The core exploit framework used by UTA0565 is identical to the kit deployed by other Chinese espionage clusters, including APT31 and UTA0560, earlier in September 2026.[2][3]
This widespread adoption points to a centralized supply chain. "This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese CNE community, where the core kit was likely shared, customized, and weaponized by multiple groups," Volexity researchers Damien Cash and Tom Lancaster noted in their analysis. Both Google and Microsoft have since issued patches for the vulnerabilities, shifting the defensive burden to organizations to ensure their browser and operating system fleets are fully updated.[1][2][3]
What to know
- Chinese threat group UTA0565 chained three zero-day vulnerabilities to breach Asian government networks.
- The attacks bypassed Chrome sandboxes and escalated Windows privileges without user interaction.
- Victims were lured to fake NGO websites via spear-phishing emails about a Hong Kong activist.
- The exploit deployed CLEANGULP, a new backdoor used for persistent espionage and data collection.
- The shared exploit framework indicates a coordinated supply chain among Chinese state-aligned hackers.
Where opinion splits
Threat Intelligence Analysts
Researchers view the shared exploit kit as evidence of a centralized Chinese cyber-espionage supply chain.
Security researchers emphasize that the simultaneous use of the same zero-day chain by multiple distinct threat groups—including UTA0565 and APT31—indicates a highly organized exploit-sharing economy. Rather than each group developing its own capabilities, a centralized quartermaster likely provisions high-end exploits to various state-aligned teams, allowing them to customize the final payload and delivery mechanisms for their specific targets.
Enterprise Network Defenders
Security teams emphasize the danger of the 'patch gap' in modern web browsers.
For network administrators, the campaign highlights the critical window between a vulnerability's discovery in open-source repositories and its deployment to stable browser builds. Because the initial Chrome flaw was patched in the Chromium source code before the update reached end users, attackers were able to reverse-engineer the fix and weaponize it against organizations that had not yet restarted their browsers to apply the pending update.
Sources
[1]VolexityThreat Intelligence ResearchersMind the Patch Gap Part 2: Fake Websites Used to Deploy Chrome/Windows 0-Day Exploits
Read on Volexity →
[2]CyberScoopThreat Intelligence ResearchersVolexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Read on CyberScoop →
[3]AviatrixThreat Intelligence ResearchersUTA0565 Exploits Chrome-Windows Zero-Day Chain in Sophisticated Campaign Against Asian Governments
Read on Aviatrix →
[4]Factlen Editorial TeamEnterprise Security DefendersSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
More in Technology
See all →Platform Policy
Meta Expands Test Limiting Facebook Page Link Posts to Two Per Month Unless Subscribed to 'Meta One'
6 sources
AI Infrastructure
SK Hynix Subsidiary Solidigm Weighs $150 Billion US IPO and First American NAND Fab
7 sources
GDPR Compliance
The Legal Bases for Processing Personal Data Under GDPR
7 sources
RISC-V Adoption
How the Open-Source RISC-V Architecture Captured 25% of the Global Chip Market
3 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




