Skip to main content
Emerging ThreatsMalware & Ransomware

China-Aligned Group Exploits Chrome, Microsoft Zero-Days

Modern office setting with a computer on a neutral surface.

"This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese computer network exploitation community, where the core kit was likely shared, customized, and weaponized by multiple groups," Volexity wrote.

The exploit chain: CVE-2026-85046, CVE-2026-87491 and CVE-2026-85880

Volexity researchers reported that a China-aligned threat group it tracks as UTA0565 exploited a linked chain of three zero-day vulnerabilities across multiple campaigns between Sept. 3 and Sept. 4, before the defects were publicly disclosed or patched. The chain combined two remote-code execution flaws in the JavaScript engine for Chromium-based browsers — CVE-2026-85046 and CVE-2026-87491 — with a Windows privilege-escalation zero-day, CVE-2026-85880, which Microsoft disclosed on Sept. 8 and identified in Windows Advanced Local Procedure Call (ALPC).

UTA0565’s lures: Chow Hang-tung, spoofed nonprofits and multiple fake websites

Volexity described UTA0565’s operational approach as notable for its use of multiple fake websites and targeted phishing. The company shared examples of phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung. In other phishing messages the group spoofed domains impersonating the Center for American Progress and China Digital Times. Researchers also identified several domains the group likely used in similar campaigns targeting media organizations, halal restaurant search websites and corporate training organizations.

CLEANGULP and reuse of a shared exploit kit

UTA0565 deployed a payload from a previously undocumented malware family Volexity is calling “CLEANGULP.” While the payload family was new to Volexity’s telemetry, the firm said the campaigns used the same components researchers had observed in earlier instances of the exploit kit across multiple Chinese threat groups. Volexity framed that reuse as evidence of a core kit shared and weaponized by several actors: “The activity reported so far reflects only two organizations’ observations; the full scope and impact are likely far broader.”

Proofpoint’s prior observations and broader group activity

Proofpoint previously observed multiple state-aligned threat groups chaining the same zero-days together in attacks since last August and attributed those incidents to APT31, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket. Proofpoint said a limited group of organizations were exposed to all three vulnerabilities in a short window and warned that attackers of other origins and motivations could strike soon as well. Volexity contrasted UTA0565’s campaigns with earlier activity, saying the group showed both technical and operational improvements over other campaigns it has observed.

How Asian government entities, media organizations, and security teams are implicated

  • Asian government entities: Volexity published examples showing UTA0565 directly targeted Asian government recipients with phishing messages urging public statements in support of Chow Hang-tung, signaling a deliberate political lure aimed at that audience.
  • Media organizations and niche web services: Researchers found domains tied to campaigns aimed at media outlets, halal restaurant search sites, and corporate training organizations — indicating the group tested varied sectoral lures beyond government targets.
  • Security teams and threat analysts: Volexity noted UTA0565 used previously observed exploit-kit components alongside a new CLEANGULP payload and multiple fake sites. That combination — chained Chromium engine flaws plus a Windows ALPC escalation — represents the specific technical signature analysts will associate with these campaigns.

Volexity emphasized an operational refinement in UTA0565’s work: “UTA0565’s use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns observed by Volexity, both in the mechanics of the exploitation and the presentation to end users,” and added that “Using real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.”

The picture painted by Volexity and Proofpoint is one of reuse and rapid adoption: multiple actors chaining the same zero-days, shared exploit-kit components, and a fresh payload family appearing in at least one tracked campaign. As Volexity cautioned, the incidents it and another firm observed are likely a subset of a broader phenomenon — a coordinated or at least collaboratively enabled set of operations within the China-aligned exploitation community.

Read the original CyberScoop report: https://cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/