UTA0565 Used Fake Websites to Deliver Chrome and Windows Zero-Day Exploits
Volexity linked Chinese APT actor UTA0565 to phishing campaigns using fake websites and chained Chrome and Windows zero-days to deliver CLEANGULP malware.
Volexity linked Chinese APT actor UTA0565 to phishing campaigns using fake websites and chained Chrome and Windows zero-days to deliver CLEANGULP malware.
Volexity reports that UTA0560 and JungleBamboo used the same Chrome–Windows exploit chain in phishing campaigns, despite a gap between Chromium fixes and Chrome releases, to deploy distinct backdoors and credential-stealing malware.
Volexity traced UTA0533’s compromise of SonicWall SMA 1000 appliances to two zero-days, detailing the exploit chain, malware, post-compromise activity, indicators, and available patches.