UTA0565 Used Fake Websites to Deliver Chrome and Windows Zero-Day Exploits

Summary
Volexity linked Chinese APT actor UTA0565 to phishing campaigns using fake websites and chained Chrome and Windows zero-days to deliver CLEANGULP malware.
Key points
- UTA0565 used the exploit chain in campaigns on September 3–4, 2026, while the vulnerabilities were unpatched: Chrome CVE-2026-85046 and CVE-2026-87491, and Windows CVE-2026-85880.
- Phishing emails targeting Asian government entities impersonated China Digital Times and the Center for American Progress; spoofed sites hosted or loaded the exploit code.
- The exploit chain downloaded chrome_cleanup.exe, a previously undocumented malware family Volexity tracks as CLEANGULP.
- CLEANGULP can install under %LOCALAPPDATA%, persist via a scheduled task, run commands, list processes, transfer files, and execute beacon object files.
- The analyzed sample communicated over HTTP with thecovnresation[.]com, using encrypted and Base64-encoded beacon traffic.
- Volexity found additional suspected attacker-controlled domains and said the exploit kit’s use by multiple groups may indicate sharing across Chinese cyber-espionage actors.
Article Details
- Attack Vectors
- UTA0565 sent phishing emails to Asian government entities and, in another campaign, emails masquerading as the Center for American Progress. The emails linked to attacker-controlled websites spoofing legitimate organizations.
- The live spoofed website loaded legitimate-looking content and a hidden /config.html iframe containing the Chrome and Windows exploit chain.
- The exploit chain downloaded chrome_cleanup.exe, removed its Mark of the Web, and launched it through the Windows shell using COM.
- Volexity assessed with high confidence, based on partial analysis, that the resulting CLEANGULP payload could persist through a scheduled task and accept commands for shell execution, process listing, file transfer, and beacon object file execution.
- Defensive Notes
- Potential investigation artifacts include %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe and a scheduled task named MicrosoftIME.
- Volexity observed CLEANGULP communicate with thecovnresation[.]com over HTTP, including an initial POST to /beacon/pre-register.
- Volexity invites organizations that believe they were targeted by a similar attack to request an assessment.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | americanprgoress[.]top | Attacker-controlled spoof of the Center for American Progress that hosted the exploit chain. |
| DOMAIN | borneobulletins[.]top | Spoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled. |
| DOMAIN | chinadigitaltimes[.]top | Attacker-controlled spoof of China Digital Times linked in phishing emails. |
| DOMAIN | halal-navi[.]net | Spoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled. |
| DOMAIN | halaltak[.]net | Spoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled. |
| DOMAIN | outsourcingwise[.]net | Spoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled. |
| DOMAIN | personclouds[.]com | Additional domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled. |
| DOMAIN | thecovnresation[.]com | Hardcoded CLEANGULP C2 domain, also among domains Volexity believes were attacker-controlled. |
| DOMAIN | thecovnresation[.]net | Spoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled. |
| IPV4 | 96[.]9[.]125[.]52 | Hosting IP that Volexity found had served the spoofed China Digital Times website. |
| MD5 | 177652713dad3c128bd9195abf2b7603 | MD5 hash of the chrome_cleanup.exe CLEANGULP payload. |
| SHA1 | 668aa5551315ab26b67118fbb29f8e4560a1e1af | SHA1 hash of the chrome_cleanup.exe CLEANGULP payload. |
| SHA256 | 8858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cb | SHA256 hash of the chrome_cleanup.exe CLEANGULP payload. |
| URL | hxxps[:]//americanprgoress[.]top/chrome_cleanup[.]exe | Payload URL from which the exploit chain downloaded CLEANGULP. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationCLEANGULP was heavily obfuscated using control flow flattening and indirect calls.T1053.005 · Scheduled TaskVolexity assessed that CLEANGULP could persist through a scheduled task named MicrosoftIME.T1068 · Exploitation for Privilege EscalationThe chain included a Microsoft Windows local privilege escalation exploit.T1071.001 · Web ProtocolsVolexity observed CLEANGULP use HTTP for C2 traffic, including its initial registration beacon.T1105 · Ingress Tool TransferThe exploit chain downloaded the chrome_cleanup.exe payload from the attacker-controlled website.T1189 · Drive-by CompromiseA spoofed website loaded a hidden iframe containing a browser exploit chain for visitors.T1203 · Exploitation for Client ExecutionThe website's hidden iframe contained exploits for two Google Chrome zero-day vulnerabilities.T1553.005 · Mark-of-the-Web BypassThe exploit chain removed Mark of the Web from chrome_cleanup.exe before launching it.T1559.001 · Component Object ModelThe exploit chain launched the downloaded executable through the Windows shell using COM.T1566.002 · Spearphishing LinkUTA0565 sent phishing emails containing links to attacker-controlled spoofed websites.T1573.001 · Symmetric CryptographyCLEANGULP encrypted its C2 registration request and response bodies with AES-256-GCM.
CVE
CVE-2026-85046a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistentCVE-2026-85880chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) actors.CVE-2026-87491the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT)
People
Threat Actors
Malware
Vendors
GoogleVolexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different ChineseMicrosoftuse of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) actors.
Products
Google Chromepublished a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different ChineseMicrosoft Windowsuse of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) actors.