Hackers Clone Trusted Websites to Chain Chrome and Windows Zero-Days in Espionage Campaign
Want more insights like this?
Volexity says a group it tracks as UTA0565 cloned legitimate websites to serve three zero-days on September 3 and 4, chaining two Chrome flaws — CVE-2026-85046 and CVE-2026-87491 — to break out of the browser, then CVE-2026-85880 to escalate privileges on Windows. Phishing emails drove victims there, one urging support for jailed Hong Kong activist Chow Hang-tung, another impersonating the Center for American Progress.
Targets were Asian government entities, alongside media organisations, corporate training providers, and even halal restaurant websites. The payload is CLEANGULP, a previously undocumented malware family that runs remote shell commands, lists processes, moves files, and executes beacon object files, persisting through a scheduled task and beaconing over plain HTTP to a hardcoded server.
Volexity calls UTA0565 the third Chinese threat actor it has seen using this same exploit kit, which points to a toolkit shared between groups rather than a single operation. Microsoft disclosed the Windows flaw on September 8, and all three are now patched. No CVSS scores have been published. Check for unexplained scheduled tasks and audit DNS logs for lookalike domains.
Source: Cyber Security News