Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
Volexity links third Chinese actor UTA0565 to typosquatted phishing sites chaining Chrome and Windows zero-days to deploy CLEANGULP backdoor.
Volexity attributes a third Chinese-linked espionage cluster, UTA0565, to September 2026 phishing operations against Asian government entities using cloned sites like chinadigitaltimes[.]top. Hidden iframes chained Chrome V8 type confusion CVE-2026-85046 (a patch-gap flaw fixed in Chromium source but not yet in stable Chrome), V8 sandbox escape CVE-2026-87491, and Windows kernel LPE CVE-2026-85880 for full code execution. The final payload, CLEANGULP, is an 893 KB obfuscated C backdoor persisting as MicrosoftIME.exe via a scheduled task, with shell, file transfer, process enumeration, and BOF commands over AES-256-GCM encrypted HTTP C2. Proofpoint reports the shared BlueMoon exploit framework has at least four espionage users with a suspected China nexus, indicating rapid spread of the capability.