Skip to main content
Emerging ThreatsMalware & Ransomware

Chinese Hackers Exploit Chrome-Windows Zero-Days to Deploy CLEANGULP Malware

A city street scene with a laptop on a small table, scattered papers, and a cup of coffee nearby.

"UTA0565 masqueraded as various entities including media organizations and a non-governmental organization (NGO)," Volexity researchers Damien Cash and Tom Lancaster said in an analysis published this week.

UTA0565’s lures: fake sites, spoofed emails, and a political pretext

Researchers observed UTA0565 deploying convincingly styled phishing messages on September 3 and 4, 2026 that targeted Asian government entities. The emails urged recipients to support Hong Kong activist Chow Hang-tung — who was sentenced to seven years and three months earlier this month — and impersonated the Center for American Progress (CAP). Links in those messages pointed to spoofed domains, specifically chinadigitaltimes[.]top and americanprgoress[.]top, which replicated the look of China Digital Times and CAP and loaded an additional HTML element via a hidden iframe.

The Chrome–Windows zero‑day chain: CVE-2026-85046, CVE-2026-87491 and CVE-2026-85880

Volexity’s analysis identifies the exploitation chain as combining two Google Chrome vulnerabilities (CVE-2026-85046 and CVE-2026-87491) with a Microsoft Windows Advanced Local Procedure Call vulnerability (CVE-2026-85880). The trio was used as zero-days to escape the browser sandbox and achieve remote code execution on victims’ systems. The exploit sequence was delivered through an HTML element named "config.html" hosted on the fake sites and was tied to the BlueMoon exploit kit.

BlueMoon exploit kit, config.html, and the chrome_cleanup.exe dropper

According to the report, the hidden iframe loaded a "config.html" object that used the BlueMoon exploit kit to chain the three vulnerabilities. The final stage of that chain — described as the "pp" shellcode — downloaded an executable named chrome_cleanup.exe from the bogus domain. That executable is identified as the CLEANGULP malware family and was compiled using the Microsoft Visual C Compiler.

CLEANGULP capabilities and its mimicry of legitimate media

CLEANGULP exposes a concise, task‑oriented command set. Volexity lists the malware's built-in capabilities as:

  • shell — to run a command
  • ps — to list running processes
  • upload — to upload a file
  • download — to download a file
  • bof — to execute a beacon object file (BOF)

Notably, CLEANGULP contains a hard‑coded HTTP command‑and‑control domain, thecovnresation[.]com, an apparent attempt to mimic the legitimate non‑profit media site theconversation[.]com. That mimicry, paired with site impersonation for delivery, underscores the campaign’s emphasis on blending technical exploit chains with social‑engineering techniques.

What this means for Asian government targets, media organizations, and NGOs

Asian government entities that received the phishing emails will watch for reuse of the chinadigitaltimes[.]top and americanprgoress[.]top domains and for the hidden iframe pattern loading a config.html object linked to BlueMoon. Media organizations and NGOs copied by the actor — or whose brands were imitated — will be concerned about brand spoofing tied to exploit delivery. Incident responders will also note the CLEANGULP indicators: the chrome_cleanup.exe filename, the thecovnresation[.]com C2 domain, and the compact set of commands (shell, ps, upload, download, bof) as specific forensic fingerprints to hunt for.

Patterns of tool sharing inside the Chinese CNE community

Volexity’s report highlights a wider inference: "This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese CNE community, where the core kit was likely shared, customized, and weaponized by multiple groups." The researchers add that the activity reported so far reflects observations from only two organizations, which implies the full scope and impact are likely broader.

The immediate, verifiable facts — two days of observed exploitation (September 3–4, 2026), a three‑CVE exploit chain (CVE‑2026‑85046, CVE‑2026‑87491, CVE‑2026‑85880), the BlueMoon kit loading a config.html element, the chrome_cleanup.exe payload, the CLEANGULP command set, and the hard‑coded thecovnresation[.]com C2 domain — form a compact forensic picture. If Volexity’s hypothesis about sharing within the Chinese CNE community holds, the technical artifacts described here should appear in other investigations; the critical question left by the report is which additional actors or victims will surface next.

Read the original Volexity-based account at The Hacker News: https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html