Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

3012+ Articles
170+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
NEWS

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

China-linked UTA0565 chained Chrome and Windows zero-days via spoofed websites to deploy the new CLEANGULP backdoor against Asian targets.

Dylan H.

News Desk

September 23, 2026
3 min read

A Third Chinese Group Weaponizes the Same Exploit Chain

Researchers at Volexity have identified a third China-linked threat group, tracked as UTA0565, exploiting a chained set of Chrome and Windows zero-day vulnerabilities to deploy a previously undocumented malware family it calls CLEANGULP. Volexity observed the campaign on September 3-4, 2026, while the underlying flaws were still unpatched.

The activity follows Volexity's earlier September 9 report on two other China-linked groups, UTA0560 and JungleBamboo, using the same core exploit chain — suggesting the toolkit was shared, customized, and deployed independently by multiple operators, consistent with a coordinated effort within China's offensive cyber ecosystem.


The Exploit Chain

CVEComponentType
CVE-2026-85046Google Chrome (V8)High-severity type-confusion; code execution inside Chrome's sandbox via crafted HTML
CVE-2026-87491Google ChromeChained with CVE-2026-85046
CVE-2026-85880Windows kernelLocal privilege escalation, used to break out of the Chrome sandbox

UTA0565's campaigns stood out from the other two groups by relying on multiple fake websites to lure victims, rather than a single compromised or spoofed domain. One phishing lure sent to Asian government entities used Chinese-language messaging urging recipients to publicly support imprisoned Hong Kong activist Chow Hang-tung and amplify opposition to Chinese Communist Party suppression of June 4th commemorations.

Spoofed Infrastructure

Volexity identified several spoofed domains tied to the group with medium confidence, impersonating media outlets, corporate-training services, and restaurant directories — likely serving as exploit hosts, malware delivery points, or command-and-control infrastructure:

  • outsourcingwise[.]net
  • halal-navi[.]net
  • halaltak[.]net
  • borneobulletins[.]top
  • thecovnresation[.]net / thecovnresation[.]com

CLEANGULP Malware

The final payload — downloaded as chrome_cleanup.exe from americanprgoress[.]top — is an 893 KB Windows executable that Volexity now tracks as CLEANGULP, a previously undocumented family written in C and compiled with the Microsoft Visual C++ compiler. The binary is heavily obfuscated using control-flow flattening and indirect calls to hinder analysis.

Persistence and capabilities:

  • Installs itself at %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe
  • Creates a scheduled task named MicrosoftIME for persistence
  • Executes shell commands
  • Lists running processes
  • Uploads and downloads files
  • Executes beacon object files (BOFs)

Detection and Mitigation

  1. Apply Chrome and Windows security updates immediately — CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 should all be treated as urgent, even where vendor patches were pending at time of exploitation.
  2. Block the spoofed domains listed above at the network and DNS layer.
  3. Hunt for MicrosoftIME.exe under %LOCALAPPDATA%\Microsoft\IME\ and a scheduled task named MicrosoftIME.
  4. Investigate suspicious Chrome child-process activity, particularly processes spawned outside normal browser behavior following a page visit.
  5. Treat phishing lures referencing politically sensitive topics (e.g., Hong Kong activism, June 4th) targeting government or NGO staff as a high-confidence indicator of targeted, not commodity, activity.

Sources

  • Volexity — Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
  • CyberScoop — Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
#Zero-Day#Chrome#Windows#Malware#China#UTA0565#CVE

Related Articles

China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy GRIMWEDGE

UTA0560 chained 3 Chrome and Windows zero-days in a phishing campaign against NGOs, deploying the GRIMWEDGE backdoor via a hijacked university site.

3 min read

New 'BlueMoon' Exploit Kit Chains Chrome and Windows Zero-Days for Espionage

At least four espionage-linked threat clusters adopted the BlueMoon exploit kit within days, chaining Chrome and Windows zero-days for backdoor access.

4 min read

Google Patches Actively Exploited Chrome Zero-Day

Google has released an emergency Chrome update to fix a zero-day vulnerability being actively exploited in targeted attacks against journalists and activists.

2 min read
Back to all News