China-Linked UTA0565 Chained Chrome and Windows Zero-Days via Cloned Websites to Deploy CLEANGULP Backdoor
Volexity attributes a third Chinese espionage cluster, UTA0565, to September 3-4, 2026 attacks on Asian government entities that used cloned legitimate websites and the shared BlueMoon exploit kit to chain three zero-days (CVE-2026-85046, CVE-2026-87491,…
Volexity tracks a third China-linked espionage cluster, UTA0565, which on September 3-4, 2026 — before the flaws were disclosed or patched — targeted Asian government entities with phishing emails impersonating the Center for American Progress and themed around imprisoned Hong Kong activist Chow Hang-tung. Victims were lured to cloned, typosquatted versions of the Center for American Progress and China Digital Times websites (including chinadigitaltimes[.]top), where a hidden iframe loaded the BlueMoon exploit kit. The kit chained three zero-days: CVE-2026-85046, described as a Chrome V8 type-confusion patch-gap flaw that was fixed in Chromium source but not yet in stable Chrome, and CVE-2026-87491 — described as a V8 sandbox escape in one report and as a JavaScript-engine remote-code-execution flaw alongside CVE-2026-85046 in another — followed by CVE-2026-85880, a Windows Advanced Local Procedure Call (ALPC) kernel privilege-escalation zero-day that Microsoft disclosed on September 8, 2026, to escape the browser sandbox and gain full code execution. The final payload, CLEANGULP, is a previously undocumented 893 KB obfuscated C implant, described as MSVC-built, that persists as MicrosoftIME.exe via a scheduled task and supports shell commands, process enumeration, file upload/download, and beacon object file (BOF) execution, communicating over AES-256-GCM-encrypted HTTP with a C2 domain mimicking theconversation.com (thecovnresation[.]com). Proofpoint reports the shared BlueMoon exploit framework has at least four espionage users with a suspected China nexus — groups it has linked to APT31, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket — and Volexity assesses the kit's shared use reflects coordinated activity across multiple Chinese computer network exploitation groups with broader impact than currently observed.
- Actor: UTA0565, a third Chinese-linked espionage cluster tracked by Volexity; all four reports agree on the actor, dates, targets, and CVEs
- Attack window: September 3-4, 2026, before the vulnerabilities were disclosed or patched; Microsoft disclosed CVE-2026-85880 on September 8, 2026
- Zero-day chain: CVE-2026-85046 and CVE-2026-87491 (Chromium) plus CVE-2026-85880 (Windows ALPC kernel privilege escalation)
Coverage timelineoldest first · each row is one article
- · 4d agoChinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
GBHackers· 85
Volexity links third Chinese actor UTA0565 to typosquatted phishing sites chaining Chrome and Windows zero-days to deploy CLEANGULP backdoor.
- · 4d agoHackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits
Cyber Security News· 0
A cyber campaign uses cloned legitimate websites to trigger zero-day exploits in Chrome and Windows, targeting Asian government entities for espionage.
- · 4d ago
Vulnerabilities in this storyAll →
- CVE-2026-850468.849%Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)published · Google Chrome KEV PoC ×5