UTA0565 Used Fake Websites to Deliver Chrome and Windows Zero-Day Exploits

· Original article ↗

Summary

Volexity linked Chinese APT actor UTA0565 to phishing campaigns using fake websites and chained Chrome and Windows zero-days to deliver CLEANGULP malware.

Key points

  • UTA0565 used the exploit chain in campaigns on September 3–4, 2026, while the vulnerabilities were unpatched: Chrome CVE-2026-85046 and CVE-2026-87491, and Windows CVE-2026-85880.
  • Phishing emails targeting Asian government entities impersonated China Digital Times and the Center for American Progress; spoofed sites hosted or loaded the exploit code.
  • The exploit chain downloaded chrome_cleanup.exe, a previously undocumented malware family Volexity tracks as CLEANGULP.
  • CLEANGULP can install under %LOCALAPPDATA%, persist via a scheduled task, run commands, list processes, transfer files, and execute beacon object files.
  • The analyzed sample communicated over HTTP with thecovnresation[.]com, using encrypted and Base64-encoded beacon traffic.
  • Volexity found additional suspected attacker-controlled domains and said the exploit kit’s use by multiple groups may indicate sharing across Chinese cyber-espionage actors.

Article Details

Attack Vectors
  • UTA0565 sent phishing emails to Asian government entities and, in another campaign, emails masquerading as the Center for American Progress. The emails linked to attacker-controlled websites spoofing legitimate organizations.
  • The live spoofed website loaded legitimate-looking content and a hidden /config.html iframe containing the Chrome and Windows exploit chain.
  • The exploit chain downloaded chrome_cleanup.exe, removed its Mark of the Web, and launched it through the Windows shell using COM.
  • Volexity assessed with high confidence, based on partial analysis, that the resulting CLEANGULP payload could persist through a scheduled task and accept commands for shell execution, process listing, file transfer, and beacon object file execution.
Defensive Notes
  • Potential investigation artifacts include %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe and a scheduled task named MicrosoftIME.
  • Volexity observed CLEANGULP communicate with thecovnresation[.]com over HTTP, including an initial POST to /beacon/pre-register.
  • Volexity invites organizations that believe they were targeted by a similar attack to request an assessment.

Indicators of compromise

TypeIndicatorContext
DOMAINamericanprgoress[.]topAttacker-controlled spoof of the Center for American Progress that hosted the exploit chain.
DOMAINborneobulletins[.]topSpoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled.
DOMAINchinadigitaltimes[.]topAttacker-controlled spoof of China Digital Times linked in phishing emails.
DOMAINhalal-navi[.]netSpoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled.
DOMAINhalaltak[.]netSpoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled.
DOMAINoutsourcingwise[.]netSpoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled.
DOMAINpersonclouds[.]comAdditional domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled.
DOMAINthecovnresation[.]comHardcoded CLEANGULP C2 domain, also among domains Volexity believes were attacker-controlled.
DOMAINthecovnresation[.]netSpoofed domain Volexity assessed with medium confidence was used by UTA0565; believed to be attacker-controlled.
IPV496[.]9[.]125[.]52Hosting IP that Volexity found had served the spoofed China Digital Times website.
MD5177652713dad3c128bd9195abf2b7603MD5 hash of the chrome_cleanup.exe CLEANGULP payload.
SHA1668aa5551315ab26b67118fbb29f8e4560a1e1afSHA1 hash of the chrome_cleanup.exe CLEANGULP payload.
SHA2568858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cbSHA256 hash of the chrome_cleanup.exe CLEANGULP payload.
URLhxxps[:]//americanprgoress[.]top/chrome_cleanup[.]exePayload URL from which the exploit chain downloaded CLEANGULP.

MITRE ATT&CK

CVE

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles