Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Chinese actor UTA0565 chains three Chrome and Windows zero-days via fake NGO media sites to drop CLEANGULP backdoor malware on Asian government targets.
Volexity detected attacks on September 3-4, 2026 in which UTA0565 chained Chrome flaws CVE-2026-85046 and CVE-2026-87491 with Windows ALPC bug CVE-2026-85880 to escape the browser sandbox and gain remote code execution. Phishing emails impersonating the Center for American Progress and themed around Hong Kong activist Chow Hang-tung targeted Asian government entities, luring victims to spoofed domains loading the BlueMoon exploit kit via hidden iframe. The final shellcode dropped CLEANGULP, an MSVC-built implant with shell, process listing, upload, download, and BOF execution capabilities, using thecovnresation[.]com for HTTP command-and-control. Volexity believes the shared exploit kit reflects coordinated use across multiple Chinese CNE groups with broader impact than currently observed.