apt-espionage Volexity

Third China-Linked Actor Weaponises Chrome–Windows Zero-Day Chain via Fake Websites, Deploys CLEANGULP Backdoor

A third China-linked APT actor tracked as UTA0565 has reused the same Chrome and Windows zero-day chain previously tied to two other Chinese groups—this time delivering the newly named CLEANGULP backdoor through spoofed websites. Volexity disclosed the findings on 21 September 2026, documenting campaigns on 3–4 September while the flaws remained unpatched.

Third China-Linked Actor Weaponises Chrome–Windows Zero-Day Chain via Fake Websites, Deploys CLEANGULP Backdoor

A third China-linked advanced persistent threat actor has been observed using the same chained zero-day exploits in Google Chrome and Microsoft Windows that two other Chinese groups abused earlier this month—this time delivering a previously undocumented backdoor through carefully spoofed websites. Cybersecurity firm Volexity disclosed the findings on 21 September 2026, tracking the new cluster as UTA0565 and naming the payload CLEANGULP. The campaigns ran on 3–4 September 2026 while the flaws were still unpatched, extending a “patch gap” that has already drawn intense scrutiny from governments, NGOs and diplomatic organisations.

Volexity’s earlier report on 9 September documented two separate Chinese APT clusters exploiting CVE-2026-85046 and CVE-2026-87491 in Chrome together with CVE-2026-85880, a Windows local privilege-escalation bug, to escape the browser sandbox and seize SYSTEM-level control. UTA0565 reused that identical exploit kit but changed how victims were lured. Instead of relying solely on direct phishing links to exploit pages, the operators stood up lookalike sites that pulled legitimate content from real organisations and injected the exploit chain through a hidden iframe.

Spoofed media and NGO brands

In one campaign aimed at Asian government entities, phishing emails written in Chinese urged recipients to support imprisoned Hong Kong activist Chow Hang-tung and amplify criticism of Chinese Communist Party suppression of June 4 commemorations. The messages linked to a domain impersonating China Digital Times (`chinadigitaltimes[.]top`). In another wave, emails masqueraded as the Center for American Progress and pointed to a typosquat (`americanprgoress[.]top`) that still loaded most of its décor from the legitimate americanprogress.org site while embedding the Chrome–Windows exploit kit in an additional HTML element.

Volexity assessed that the core exploit binaries (internally labelled p1 and p2) matched earlier campaigns. The main functional change was the follow-on payload: instead of downloading `msgbox.exe` via a `cmd.exe`/`curl` pattern, the kit downloaded `chrome_cleanup.exe` in-process, stripped its Mark of the Web, and launched it via the Windows shell using COM. That binary is CLEANGULP—an 893 KB Win64 executable obfuscated with control-flow flattening and indirect calls.

What CLEANGULP does

Dynamic analysis indicates CLEANGULP installs to `%LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe` and persists through a scheduled task named “MicrosoftIME.” Supported commands include shell execution, process listing, file upload and download, and execution of beacon object files (BOF). Command-and-control traffic used HTTP to a typosquat of The Conversation (`thecovnresation[.]com`), with request and response bodies encrypted using AES-256-GCM and a custom Base64 alphabet. After registration, the implant awaited operator approval before further tasking—an operational discipline consistent with espionage rather than smash-and-grab crimeware.

Pivoting on domain-registration patterns, Volexity uncovered additional spoofed hostnames with medium confidence, covering media brands, halal restaurant search sites and corporate-training organisations. The breadth of decoys suggests UTA0565 is casting a wide net across diplomatic, civil-society and regional audiences while recycling a shared exploit framework. Proofpoint has independently identified other users of the same kit. Volexity concludes that the pattern points to coordinated sharing inside the Chinese computer-network exploitation community, with each group customising the kit’s presentation and final malware.

Forensix previously covered the first Volexity disclosure on the Chrome–Windows chain. Monday’s Part 2 report matters because it shows the kit is no longer confined to two clusters: a third actor improved the social-engineering wrapper, swapped in a new implant family, and hit targets while patches were still unavailable. Organisations that only blocked indicators from the first report may still be exposed to UTA0565’s decoy domains and CLEANGULP persistence.

What targeted organisations should do now

  • Ensure Chrome and Windows are fully patched for CVE-2026-85046, CVE-2026-87491 and CVE-2026-85880 across all user endpoints, including VIP and diplomatic devices.
  • Treat lookalike domains as hostile. Block and investigate typosquats of trusted media and NGO brands, especially `.top` and near-miss spellings registered in early September 2026.
  • Hunt for CLEANGULP artefacts: `MicrosoftIME.exe` under LocalAppData\Microsoft\IME, scheduled tasks named MicrosoftIME, and HTTP beacons to Conversation typosquats.
  • Isolate high-risk browsing for staff who handle human-rights, China policy or diplomatic correspondence—remote browser isolation reduces the blast radius of drive-by exploit kits.
  • Preserve evidence before remediation: browser crash dumps, scheduled-task XML, and network PCAP around first beacon time support DFIR attribution and timeline reconstruction.

Evidence status

  • Confirmed: Volexity documented UTA0565 campaigns on 3–4 September 2026 using the shared Chrome–Windows zero-day chain and CLEANGULP; technical overlap with prior kits is detailed in their Part 2 report.
  • Reported: Proofpoint observed additional users of the same exploit kit; decoy domains and C2 typosquats are published with Volexity’s indicators.
  • Unconfirmed: Full victimology beyond Asian government and NGO-themed lures, and the precise relationship between UTA0565 and other Chinese CNE clusters sharing the kit.

In brief

  • Volexity says China-linked actor UTA0565 used fake websites to deliver the same Chrome and Windows zero-day chain previously tied to two other APT groups.
  • The final payload is CLEANGULP, a new backdoor that persists as a fake Microsoft IME binary and beacons to a Conversation typosquat.
  • Patch browsers and Windows immediately, block spoofed media domains, and hunt for CLEANGULP persistence on exposed endpoints.

Sources & References

← All News Tools