VYPR
researchPublished Sep 21, 2026· 1 source

Chinese APT UTA0565 Leverages Chrome and Windows Zero-Days via Fake Websites

A third Chinese APT actor, UTA0565, has been observed exploiting chained zero-day vulnerabilities in Google Chrome and Microsoft Windows, using sophisticated fake websites to deliver the exploits.

A new campaign by a Chinese advanced persistent threat (APT) actor, identified by Volexity as UTA0565, has been uncovered exploiting chained zero-day vulnerabilities in Google Chrome and Microsoft Windows. These attacks, which occurred on September 3-4, 2026, took place while the vulnerabilities remained unpatched, highlighting a critical window of exploitation. This actor's methodology distinguished itself by employing multiple deceptive websites designed to lure unsuspecting victims.

In one observed instance, UTA0565 targeted Asian government entities with a Chinese-language phishing email. The email urged recipients to publicly support Hong Kong activist Chow Hang-tung and protest against the Chinese Communist Party's suppression of a June 4th commemoration. This tactic leverages politically charged content to increase the likelihood of engagement and exploit victim trust. Another campaign saw the threat actor impersonate the Center for American Progress, sending a phishing email that directed users to a spoofed domain.

The fake websites utilized by UTA0565 were meticulously crafted to mimic legitimate online presences. One such site, chinadigitaltimes[.]top, was designed to look identical to the legitimate China Digital Times website. While this specific spoofed site was no longer accessible at the time of analysis, network data indicated its identical appearance to the original. Another example, americanprgoress[.]top, typosquatted the Center for American Progress domain and, while live, loaded most of its content from the legitimate site while also embedding an iframe containing malicious components.

These embedded components were directly linked to the exploitation of the chained zero-day vulnerabilities: CVE-2026-85046 and CVE-2026-87491 in Google Chrome, and CVE-2026-85880 in Microsoft Windows. The exploit kit's implementation remained largely unchanged from previously documented attacks, including version checks and stage sequencing. However, the payload delivery mechanism saw an update: the config.html file was designed to download chrome_cleanup.exe in-process, remove its Mark of the Web, and execute it via the Windows shell using COM, a departure from earlier methods that relied on cmd.exe/curl.

The downloaded payload, chrome_cleanup.exe, belongs to a new malware family that Volexity has designated CLEANGULP. Written in C and heavily obfuscated using control flow flattening and indirect calls, CLEANGULP was built using the Microsoft Visual C Compiler to hinder analysis. Volexity's dynamic analysis revealed that CLEANGULP is capable of installing itself to %LOCALAPPDATA%MicrosoftIMEMicrosoftIME.exe, establishing persistence through a scheduled task named "MicrosoftIME," and executing a range of commands including running arbitrary shell commands, listing processes, uploading/downloading files, and executing beacon object files.

CLEANGULP communicates with its command-and-control (C2) server via HTTP, using a single hardcoded domain, thecovnresation[.]com, which appears to be a typosquat of the legitimate "The Conversation" website. Network traffic is encrypted using AES-256-GCM and then Base64 encoded with a custom alphabet. The AES key is derived from the SHA256 hash of this custom alphabet. Initial communication involves a registration beacon where the malware sends a UUID, and the server responds with an approval status.

Volexity's investigation into the registration patterns of domains used in these attacks uncovered several additional domains that are assessed with medium confidence to have also been utilized by UTA0565 in similar campaigns. These domains often impersonate media organizations, suggesting a broad strategy of deception and information manipulation. The discovery of CLEANGULP and UTA0565's sophisticated exploitation chain underscores the persistent threat posed by Chinese APT actors leveraging zero-day vulnerabilities for espionage and targeted attacks.

Synthesized by Vypr AI
Chinese APT UTA0565 Leverages Chrome and Windows Zero-Days via Fake Websites · VYPR