{"id":3097,"date":"2026-09-23T10:23:41","date_gmt":"2026-09-23T10:23:41","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3097"},"modified":"2026-09-23T10:23:41","modified_gmt":"2026-09-23T10:23:41","slug":"chinese-hackers-exploit-chrome-windows-zero-day-chain-to-deploy-cleangulp-malware","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3097","title":{"rendered":"Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 23, 2026<\/span><\/span><span class=\"p-tags\">Zero-Day \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEikVEmuPJKZAlboodZWejG4dGZXXejOLThyXPoOnycqTY8lznAewTW5ovv8XFJzhyjPRMXT-njudYOVWFEYCLvmEPDyUrfDTZzAmp1S4KE4DuzsDFxt8R-biL2puZZBWG36_dkhfzvpeigcPb9WJNy31oIXo6Oh3zMUzL3JG6MEr4OaGE4Yi_k5JCpohVrZ\/s1700-nu-rw-lo-l85-e365\/windows-china.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A Chinese threat actor codenamed <strong>UTA0565<\/strong> has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.<\/p>\n<p>The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser&#8217;s sandbox and achieve remote code execution.<\/p>\n<p>\u00abUTA0565 masqueraded as various entities including media organizations and a non-governmental organization (NGO),\u00bb Volexity researchers Damien Cash and Tom Lancaster <a href=\"https:\/\/www.volexity.com\/blog\/2026\/09\/21\/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits\/\" target=\"_blank\">said<\/a> in an analysis published this week. \u00abNotably, this threat actor&#8217;s campaigns differed from previously documented attacks by using multiple fake websites to deceive victims.\u00bb<\/p>\n<p>One such campaign targeted Asian government entities with Chinese- and English-language phishing emails that urged recipients to support Hong Kong activist <a href=\"https:\/\/www.nchrd.org\/2025\/10\/joint-ngo-letter-to-demand-immediate-and-unconditional-release-of-chow-hang-tung-and-lee-cheuk-yan\/\" target=\"_blank\">Chow Hang-tung<\/a> and masqueraded as the Center for American Progress (CAP). Chow was <a href=\"https:\/\/www.bbc.com\/news\/articles\/cvgyvk2djk4o\" target=\"_blank\">sentenced<\/a> to seven years and three months in prison earlier this month.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>These messages contained spoofed links pointing to \u00abchinadigitaltimes[.]top\u00bb and \u00abamericanprgoress[.]top,\u00bb which replicated the look of China Digital Times and CAP, while loading an additional HTML element via a hidden iframe.<\/p>\n<p>The HTML element (\u00abconfig.html\u00bb) is said to have used the same BlueMoon exploit kit combining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, with the final \u00abpp\u00bb shellcode downloading an executable named \u00abchrome_cleanup.exe\u00bb from the bogus domain. The payload is a malware family dubbed CLEANGULP, which is built using the Microsoft Visual C Compiler.<\/p>\n<p>It supports the following capabilities &#8211;<\/p>\n<ul>\n<li>shell, to run a command<\/li>\n<li>ps, to list running processes<\/li>\n<li>upload, to upload a file<\/li>\n<li>download, to download a file<\/li>\n<li>bof, to execute a Execution of a beacon object file (<a href=\"https:\/\/hstechdocs.helpsystems.com\/manuals\/cobaltstrike\/current\/userguide\/content\/topics\/beacon-object-files_main.htm\" target=\"_blank\">BOF<\/a>)<\/li>\n<\/ul>\n<p>Interestingly, CLEANGULP has been found to use a hard-coded domain named \u00abthecovnresation[.]com\u00bb for command-and-control (C2) over HTTP, indicating an attempt to mimic \u00ab<a href=\"https:\/\/theconversation.com\/\" target=\"_blank\">theconversation[.]com<\/a>,\u00bb a non-profit media outlet known for publishing academic research, analysis, and commentary.<\/p>\n<p>\u00abThis seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese CNE community, where the core kit was likely shared, customized, and weaponized by multiple groups,\u00bb Volexity said. \u00abThe activity reported so far reflects only two organizations&#8217; observations; the full scope and impact are likely far broader.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 23, 2026Zero-Day \/ Vulnerability A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3098,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[219,106,3411,3514,229,120,338,42,126],"class_list":["post-3097","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-chain","tag-chinese","tag-chromewindows","tag-cleangulp","tag-deploy","tag-exploit","tag-hackers","tag-malware","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3097","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3097"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3097\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3098"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3097"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3097"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3097"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}