[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvGSRpoHlqQtsyha2QJkSvN58vr8UsGN0Ep5g2abhmTA":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"f9969262-8982-4ac2-ad43-bd88315a664a","Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware","chinese-hackers-exploit-chrome-windows-zero-day-chain-to-deploy-cleangulp-malwar-47e5a4","A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break","A Chinese threat actor, UTA0565, is exploiting a chain of zero-day vulnerabilities in Google Chrome and Microsoft Windows to deploy the CLEANGULP malware. The attacks, observed in early September 2026, involve fake websites designed to trick victims into executing malicious code, ultimately achieving remote code execution.","Chinese hackers exploit Chrome-Windows zero-day chain to deploy CLEANGULP malware.","Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware Ravie LakshmananSep 23, 2026Zero-Day \u002F Vulnerability A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser's sandbox and achieve remote code execution. \"UTA0565 masqueraded as various entities including media organizations and a non-governmental organization (NGO),\" Volexity researchers Damien Cash and Tom Lancaster said in an analysis published this week. \"Notably, this threat actor's campaigns differed from previously documented attacks by using multiple fake websites to deceive victims.\" One such campaign targeted Asian government entities with Chinese- and English-language phishing emails that urged recipients to support Hong Kong activist Chow Hang-tung and masqueraded as the Center for American Progress (CAP). Chow was sentenced to seven years and three months in prison earlier this month. These messages contained spoofed links pointing to \"chinadigitaltimes[.]top\" and \"americanprgoress[.]top,\" which replicated the look of China Digital Times and CAP, while loading an additional HTML element via a hidden iframe. The HTML element (\"config.html\") is said to have used the same BlueMoon exploit kit combining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, with the final \"pp\" shellcode downloading an executable named \"chrome_cleanup.exe\" from the bogus domain. The payload is a malware family dubbed CLEANGULP, which is built using the Microsoft Visual C Compiler. It supports the following capabilities - shell, to run a command ps, to list running processes upload, to upload a file download, to download a file bof, to execute a Execution of a beacon object file (BOF) Interestingly, CLEANGULP has been found to use a hard-coded domain named \"thecovnresation[.]com\" for command-and-control (C2) over HTTP, indicating an attempt to mimic \"theconversation[.]com,\" a non-profit media outlet known for publishing academic research, analysis, and commentary. \"This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese CNE community, where the core kit was likely shared, customized, and weaponized by multiple groups,\" Volexity said. \"The activity reported so far reflects only two organizations' observations; the full scope and impact are likely far broader.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Google Chrome, Malware, Microsoft Windows, Phishing, Vulnerability, Web Security ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fchinese-hackers-exploit-chrome-windows.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEikVEmuPJKZAlboodZWejG4dGZXXejOLThyXPoOnycqTY8lznAewTW5ovv8XFJzhyjPRMXT-njudYOVWFEYCLvmEPDyUrfDTZzAmp1S4KE4DuzsDFxt8R-biL2puZZBWG36_dkhfzvpeigcPb9WJNy31oIXo6Oh3zMUzL3JG6MEr4OaGE4Yi_k5JCpohVrZ\u002Fs1600\u002Fwindows-china.jpg","2026-09-23T08:29:24+00:00","2026-09-23T10:00:20.780481+00:00",9,[18,21,24,26],{"name":19,"type":20},"UTA0565","threat_actor",{"name":22,"type":23},"Google Chrome","product",{"name":25,"type":23},"Microsoft Windows",{"name":27,"type":28},"Microsoft","vendor","574f766a-fb3f-487c-8d2c-0720ae75471b",{"id":29,"icon":31,"name":32,"slug":33},null,"Zero-day","zero-day",[35,37,42,47],{"category":36},{"id":29,"icon":31,"name":32,"slug":33},{"category":38},{"id":39,"icon":31,"name":40,"slug":41},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":48},{"id":49,"icon":31,"name":50,"slug":51},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[53,57,59,62,66,68,71],{"type":54,"value":55,"context":56},"cve","CVE-2026-85046","Google Chrome vulnerability exploited in chain",{"type":54,"value":58,"context":56},"CVE-2026-87491",{"type":54,"value":60,"context":61},"CVE-2026-85880","Windows Advanced Local Procedure Call vulnerability exploited in chain",{"type":63,"value":64,"context":65},"domain","chinadigitaltimes[.]top","Fake website domain used for phishing",{"type":63,"value":67,"context":65},"americanprgoress[.]top",{"type":51,"value":69,"context":70},"CLEANGULP","Malware family deployed by threat actor",{"type":63,"value":72,"context":73},"thecovnresation[.]com","Command-and-control domain for CLEANGULP malware"]