<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Hackers Clone Trusted Websites to Chain Chrome and Windows Zero-Days in Espionage Campaign

China-linked hackers exploited Chrome and Windows flaws, targeting Asian governments and media groups with new malware CLEANGULP.
Content Team

Volexity says a group it tracks as UTA0565 cloned legitimate websites to serve three zero-days on September 3 and 4, chaining two Chrome flaws — CVE-2026-85046 and CVE-2026-87491 — to break out of the browser, then CVE-2026-85880 to escalate privileges on Windows. Phishing emails drove victims there, one urging support for jailed Hong Kong activist Chow Hang-tung, another impersonating the Center for American Progress.

Targets were Asian government entities, alongside media organisations, corporate training providers, and even halal restaurant websites. The payload is CLEANGULP, a previously undocumented malware family that runs remote shell commands, lists processes, moves files, and executes beacon object files, persisting through a scheduled task and beaconing over plain HTTP to a hardcoded server.

Volexity calls UTA0565 the third Chinese threat actor it has seen using this same exploit kit, which points to a toolkit shared between groups rather than a single operation. Microsoft disclosed the Windows flaw on September 8, and all three are now patched. No CVSS scores have been published. Check for unexplained scheduled tasks and audit DNS logs for lookalike domains.

Source: Cyber Security News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo