Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Volexity says China-linked UTA0565 exploited Chrome and Windows zero-days against Asian governments.
Volexity said China-aligned UTA0565 exploited three zero-days in Chrome and Windows on September 3-4, 2026, before the flaws were disclosed or patched. CVE-2026-85046 and CVE-2026-87491 are remote-code-execution bugs in Chromium's JavaScript engine, and CVE-2026-85880 is a Windows Advanced Local Procedure Call privilege-escalation zero-day Microsoft disclosed on September 8. The group emailed Asian government entities with lures about imprisoned Hong Kong activist Chow Hang-tung and spoofed domains impersonating the Center for American Progress and China Digital Times, deploying previously undocumented malware CLEANGULP. Volexity said the same exploit kit was shared across Chinese groups that Proofpoint has linked to APT31, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket.