Advertisement

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

Summary: A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

A China-linked hacking group has been observed exploiting a powerful chain of Google Chrome and Microsoft Windows zero-day vulnerabilities to compromise targets through carefully constructed fake websites.

The threat actor, tracked by Volexity as UTA0565, exploited three vulnerabilities together to escape Chrome’s security sandbox and achieve remote code execution on Windows systems. The attacks were detected on September 3 and 4, 2026, while the vulnerabilities were still being exploited as zero-days.

The campaign ultimately deployed a previously undocumented malware family called CLEANGULP, giving attackers extensive control over compromised computers.

Advertisement
Three Vulnerabilities Combined Into One Attack

The exploit chain combines two vulnerabilities in Google Chrome with a third vulnerability affecting Windows Advanced Local Procedure Call (ALPC):

CVE-2026-85046 and CVE-2026-87491 affect Chrome, while CVE-2026-85880 affects Windows.

Together, the vulnerabilities allow attackers to move beyond the security boundaries normally surrounding browser content. The Chrome vulnerabilities provide the initial exploitation path, while the Windows flaw enables the attackers to escape the browser sandbox and execute code on the underlying operating system.

The vulnerabilities were delivered using an exploit framework known as BlueMoon, which has already appeared in other campaigns involving the same Chrome-Windows vulnerability chain.

The use of several vulnerabilities together is particularly significant because modern browsers are designed around multiple layers of isolation. Compromising the browser itself is often insufficient to fully control a computer; attackers must also escape its sandbox.

A chain combining browser and operating-system vulnerabilities can overcome both defenses.

Fake News and NGO Websites Lured Victims

Rather than directly attacking systems exposed to the internet, UTA0565 relied on targeted social engineering.

Volexity observed the group impersonating several organizations, including media outlets and a non-governmental organization. One campaign targeted Asian government entities with phishing emails written in Chinese and English.

The messages encouraged recipients to support Hong Kong activist Chow Hang-tung and impersonated the Center for American Progress.

Links inside the messages directed victims to fake domains designed to resemble legitimate websites, including replicas of China Digital Times and the Center for American Progress.

The counterfeit pages contained hidden iframes that silently loaded the BlueMoon exploit kit.

This meant the visible website could appear relatively normal while the exploitation process occurred in the background.

If the victim’s browser and Windows installation were vulnerable, simply visiting the malicious infrastructure could provide the attackers with a path toward executing code on the machine.

CLEANGULP Provides Remote Control

After successfully exploiting the system, the final shellcode downloaded an executable named chrome_cleanup.exe.

Despite its legitimate-looking name, the executable contained CLEANGULP, a malware family compiled using Microsoft’s Visual C compiler.

The backdoor provides attackers with several capabilities, including executing shell commands, listing running processes, uploading and downloading files, and running Beacon Object Files (BOFs).

BOFs are small programs that can be executed directly inside certain post-exploitation frameworks. Their use allows attackers to extend malware functionality without necessarily deploying additional conventional executables to disk.

This modular approach means CLEANGULP can function as an initial foothold while operators selectively introduce additional capabilities depending on the target.

Command Infrastructure Also Mimics a Media Organization

The attackers continued their impersonation strategy even within CLEANGULP’s command-and-control infrastructure.

Researchers found the malware communicating over HTTP with a hard-coded domain namedthecovnresation[.]com.

The domain appears deliberately designed to resemble The Conversation, the legitimate nonprofit media organization known for publishing research and academic commentary.

Using domains that resemble recognizable organizations can make malicious traffic less obvious during casual inspection and fits with the campaign’s broader reliance on fake media and NGO infrastructure.

The phishing websites, payload names and command infrastructure were therefore all designed to appear more legitimate than conventional attacker-controlled systems.

Evidence Points to a Broader Chinese Exploit Ecosystem

One of the most important aspects of the investigation is that UTA0565 does not appear to be the only group using the BlueMoon exploit chain.

Volexity believes the same underlying exploit kit has been adopted by multiple Chinese cyber-espionage actors.

Researchers said the widespread use of the framework suggests coordination within the Chinese computer network exploitation community, where the core exploit kit may have been shared, modified and weaponized by several different groups.

That could significantly increase the scale of the threat.

A sophisticated browser-to-operating-system exploit chain is expensive and technically difficult to develop. Once such a capability is distributed among several operators, however, it can be reused against many different targets and combined with different malware families.

Volexity also cautioned that currently documented incidents represent observations from only two security organizations, meaning the full scope of exploitation could be considerably larger.

Browser Updates Remain a Critical Security Boundary

The campaign demonstrates why browser vulnerabilities have become particularly valuable tools for targeted espionage.

Browsers routinely process untrusted content from the internet while simultaneously operating on devices containing corporate credentials, documents, authentication sessions and access to internal systems.

Sandboxing is designed to prevent a browser vulnerability from becoming a complete endpoint compromise, but attackers increasingly search for additional operating-system vulnerabilities that allow them to escape those restrictions.

The BlueMoon chain does exactly that.

For organizations, particularly government agencies and companies handling sensitive information, rapid deployment of Chrome and Windows security updates remains one of the most effective defenses against campaigns of this type.

The UTA0565 operation also reinforces a broader lesson from modern espionage campaigns: sophisticated exploitation increasingly combines technical zero-days with convincing social engineering.

Attackers do not necessarily need victims to download a suspicious executable or enable a malicious document. A convincing email, a carefully cloned website and an unpatched browser can sometimes be enough to establish the initial compromise.

Advertisement

Key facts

  • A Chinese threat actor codenamed UTA0565 is exploiting a Chrome-Windows zero-day exploit chain
  • Attacks were detected on September 3 and 4, 2026
  • The exploit chain involves two vulnerabilities in Google Chrome (CVE-2026-85046, CVE-2026-87491)
  • The exploit chain includes one vulnerability in Windows Advanced Local Procedure Call (CVE-2026-85880)
  • The threat actor uses fake websites to deliver the exploit
  • CLEANGULP malware is deployed as a result of the exploit chain

Why it matters

The exploitation of zero-day vulnerabilities in widely used software like Chrome and Windows by sophisticated threat actors highlights persistent supply chain risks. Such attacks can lead to widespread compromise, impacting critical infrastructure and enterprise security, and underscore the ongoing challenge of patching and defending against advanced persistent threats.

Embedded content for: Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware