news.mlab.sh
Back to the feed
threat-intel

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

HighCVSS 8.8
Summary

Chinese threat actor UTA0565 is exploiting a chain of zero-day vulnerabilities in Chrome and Windows to deploy CLEANGULP malware, a sophisticated payload designed to execute malicious code and steal data. The campaign involved deceptive phishing emails mimicking legitimate organizations to trick victims into visiting compromised websites and installing the malware.

A Chinese threat actor, UTA0565, has been observed exploiting a chain of zero-day vulnerabilities in Google Chrome and Microsoft Windows to deploy CLEANGULP malware. The attacks, detected on September 3 and 4, 2026, involved chaining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to break out of the browser’s sandbox and achieve remote code execution. Volexity researchers Damien Cash and Tom Lancaster noted that UTA0565 masqueraded as various entities, including media organizations and a non-governmental organization (NGO), specifically using campaigns that differed from previously documented attacks by utilizing multiple fake websites to deceive victims.

One such campaign targeted Asian government entities with Chinese- and English-language phishing emails urging recipients to support Hong Kong activist Chow Hang-tung and masquerading as the Center for American Progress (CAP). Chow was sentenced to seven years and three months in prison earlier this month. These messages contained spoofed links pointing to "chinadigitaltimes[.]top" and "americanprgoress[.]top," which replicated the look of China Digital Times and CAP, while loading an additional HTML element via a hidden iframe.

The HTML element ("config.html") used the same BlueMoon exploit kit combining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, with the final "pp" shellcode downloading an executable named "chrome_cleanup.exe" from the bogus domain. The payload is a malware family dubbed CLEANGULP, which is built using the Microsoft Visual C Compiler and supports capabilities including shell, ps, upload, download, and bof (execute a beacon object file).

Interestingly, CLEANGULP has been found to use a hard-coded domain named "thecovnresation[.]com" for command-and-control (C2) over HTTP, indicating an attempt to mimic "theconversation[.]com," a non-profit media outlet known for publishing academic research, analysis, and commentary. Volexity indicated that this seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese CNE community, where the core kit was likely shared, customized, and weaponized by multiple groups. The activity reported so far reflects only two organizations' observations; the full scope and impact are likely far broader.

Read the full article at The Hacker News