Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
Volexity links third Chinese actor UTA0565 to typosquatted phishing sites chaining Chrome and Windows zero-days to deploy CLEANGULP backdoor.
Volexity attributes a third Chinese-linked espionage cluster, UTA0565, to September 2026 phishing operations against Asian government entities using cloned sites like chinadigitaltimes[.]top. Hidden iframes chained Chrome V8 type confusion CVE-2026-85046 (a patch-gap flaw fixed in Chromium source but not yet in stable Chrome), V8 sandbox escape CVE-2026-87491, and Windows kernel LPE CVE-2026-85880 for full code execution. The final payload, CLEANGULP, is an 893 KB obfuscated C backdoor persisting as MicrosoftIME.exe via a scheduled task, with shell, file transfer, process enumeration, and BOF commands over AES-256-GCM encrypted HTTP C2. Proofpoint reports the shared BlueMoon exploit framework has at least four espionage users with a suspected China nexus, indicating rapid spread of the capability.
- UTA0565 chained zero-days CVE-2026-85046, CVE-2026-87491, CVE-2026-85880 while Chrome remained unpatched
- Typosquatted clones of China Digital Times and Center for American Progress hosted hidden exploit iframes
- CLEANGULP backdoor persists via MicrosoftIME scheduled task and uses AES-256-GCM HTTP C2
- Shared BlueMoon exploit framework now used by at least four China-nexus espionage operators
- Patch-gap CVE-2026-85046 was weaponized before the fix reached stable Chrome builds
Vulnerabilities mentionedAll →
- CVE-2026-850468.849%Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)published · Google Chrome KEV PoC ×5
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | americanprgoress.top | digitaltimes[.]top , impersonating China Digital Times, and americanprgoress[.]top , a typosquat of americanprogress[.]org . Volexity found |
| domain | americanprogress.org | Digital Times, and americanprgoress[.]top , a typosquat of americanprogress[.]org . Volexity found that the China Digital Times lure had be |
| domain | borneobulletins.top | outsourcingwise[.]net , halal-navi[.]net , halaltak[.]net , borneobulletins[.]top , and both thecovnresation[.]net and thecovnresation[.]co |
| domain | chinadigitaltimes.top | semble legitimate organizations. Observed examples included chinadigitaltimes[.]top , impersonating China Digital Times, and americanprgoress |
| domain | halal-navi.net | 5 with medium confidence, including outsourcingwise[.]net , halal-navi[.]net , halaltak[.]net , borneobulletins[.]top , and both theco |
| domain | halaltak.net | dence, including outsourcingwise[.]net , halal-navi[.]net , halaltak[.]net , borneobulletins[.]top , and both thecovnresation[.]net |
Full article778 words · extracted from gbhackers.com · click to collapse
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a previously undocumented backdoor.
The activity occurred on September 3 and 4, 2026, while the targeted vulnerabilities remained unpatched in Google Chrome.
It followed Volexity’s September 9 disclosure that UTA0560 and JungleBamboo, also known as APT31 or Violet Typhoon, had used the exploit chain in separate operations.
The growing number of operators using substantially similar code points to rapid sharing or distribution of a high-end browser exploitation capability within the broader Chinese cyber-espionage ecosystem.
UTA0565 used Chinese-language phishing emails aimed at Asian government entities, including a lure urging recipients to support imprisoned Hong Kong activist Chow Hang-tung and speak out against suppression of June 4 commemorations.
In another operation, the actor impersonated the Center for American Progress.
The emails directed targets to attacker-controlled domains made to resemble legitimate organizations.
Observed examples included chinadigitaltimes[.]top, impersonating China Digital Times, and americanprgoress[.]top, a typosquat of americanprogress[.]org.
Volexity found that the China Digital Times lure had been hosted on 96.9.125[.]52 and closely replicated the authentic site’s appearance.
The Center for American Progress clone remained active during analysis and pulled much of its visible content from the legitimate website, helping it evade immediate suspicion.
However, the threat actor inserted a concealed iframe pointing to /config.html. That hidden component triggered the browser exploit chain without changing what the victim saw in the visible page.
The operation chained three vulnerabilities: Chrome V8 type-confusion vulnerability CVE-2026-85046, Chrome V8 sandbox escape CVE-2026-87491, and Windows kernel local privilege escalation CVE-2026-85880.
Together, the vulnerabilities enabled code execution in Chrome, escape from the V8 sandbox, elevation of privileges on affected Windows systems, and injection into the parent Chrome process.

CVE-2026-85046 was a “patch-gap” vulnerability: the fix had entered Chromium’s public source code but was not yet available in released Chrome builds.
That disclosure-to-release interval gave operators an opportunity to reverse engineer the upstream fix and weaponize the vulnerability against users still running vulnerable stable versions.
Volexity tracks the cluster as UTA0565, which used the same exploit framework previously associated with other China-linked espionage activity but adapted it with convincing typosquatted websites and a new payload called CLEANGULP.
APT Exploits Chrome and Windows
Proofpoint has named the shared framework BlueMoon and reported at least four espionage-focused users of the kit, most with a suspected China nexus.
UTA0565’s implementation largely retained the same embedded p1, p2, and pp components previously documented by Volexity. The key operational change was the final stage.
Rather than invoking cmd.exe and curl.exe to retrieve a payload, the modified loader downloaded chrome_cleanup.exe, removed its Mark of the Web, and launched it through the Windows shell using COM.
The final payload, chrome_cleanup.exe, is a 893 KB 64-bit executable with SHA-256 hash 8858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cb.
Volexity identified it as CLEANGULP, a previously undocumented malware family written in C, compiled with Microsoft Visual C++, and heavily obfuscated through control-flow flattening and indirect calls.
CLEANGULP installs itself as %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe and creates a scheduled task named MicrosoftIME for persistence.
Its command set supports shell execution, process enumeration, file upload and download, and beacon object file execution giving operators a flexible post-compromise platform for reconnaissance and follow-on operations.
The malware communicates with thecovnresation[.]com, a typosquat of media network The Conversation.
It uses HTTP for command-and-control traffic, encrypting request and response bodies with AES-256-GCM before Base64 encoding them with a custom alphabet.
Its first beacon registers a time-derived identifier that resembles a UUID but does not conform to RFC 9562.
Volexity linked several newly registered lookalike domains to UTA0565 with medium confidence, including outsourcingwise[.]net, halal-navi[.]net, halaltak[.]net, borneobulletins[.]top, and both thecovnresation[.]net and thecovnresation[.]com.
These domains impersonate media outlets, corporate-training services, restaurant directories, and other legitimate entities, and likely served as exploit hosts, malware-delivery points, or C2 infrastructure.
The case highlights an increasingly dangerous model: multiple operators can reuse a shared exploit core while independently replacing lures, infrastructure, loaders, and malware.
Security teams should urgently apply Chrome and Windows security updates, block the identified typosquatted domains, investigate suspicious Chrome child-process activity, and hunt for MicrosoftIME.exe under user-local application data and scheduled tasks named MicrosoftIME.
Proofpoint also warned that BlueMoon’s rapid adoption suggests the capability could spread to additional espionage and financially motivated actors.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.