Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Coordinated Chinese Cyberattacks: A Zero-Day Exploitation Chain Deploying the CLEANGULP Malware


Chinese threat actors have exploited a zero-day chain in Google Chrome and Microsoft Windows to deploy the CLEANGULP malware, which supports a range of capabilities, including running commands, listing processes, and executing beacon object files. The attacks, which have been dubbed "UTA0565," have been linked to a coordinated effort by Chinese threat actors, highlighting the evolving nature of the threat landscape and the need for organizations to stay vigilant and proactive in defending against sophisticated attacks.

  • Chinese threat actors exploited a zero-day chain in Google Chrome and Microsoft Windows to deploy the CLEANGULP malware.
  • Three vulnerabilities were chained: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880.
  • The attackers created fake websites to lure victims into downloading a phishing email, leading to remote code execution.
  • The CLEANGULP malware has capabilities including running a command, listing running processes, and executing a beacon object file.
  • The malware's use of a hard-coded domain for command-and-control (C2) over HTTP suggests a coordinated effort by multiple threat actors.
  • The attack highlights the need for organizations to stay vigilant and proactive in defending against sophisticated attacks, including regular software updates and employee education.



  • The threat landscape has witnessed a plethora of sophisticated cyberattacks in recent times, with adversaries continually adapting their tactics, techniques, and procedures (TTPs) to evade detection and maximize their impact. One such instance has come to light, involving a coordinated effort by Chinese threat actors who have exploited a zero-day chain in Google Chrome and Microsoft Windows to deploy the CLEANGULP malware.

    According to researchers at Volexity, a US-based cybersecurity firm, the attacks were detected on September 3 and 4, 2026, and involved the chaining of three vulnerabilities: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The former two vulnerabilities, which affected Chrome, were recently disclosed and have since been patched by the software giant. However, the third vulnerability, which impacted Windows Advanced Local Procedure Call (ALPC), was not as well-known and offered a vector for the attackers to break out of the browser's sandbox and achieve remote code execution.

    The attackers, who have been dubbed "UTA0565" by the researchers, employed a clever tactic to deceive their victims. They created fake websites that masqueraded as legitimate entities, including media organizations and a non-governmental organization (NGO). These websites were used to lure victims into downloading a phishing email that, when opened, would lead to a malicious HTML element being loaded via a hidden iframe. The HTML element, which contained the code "config.html," utilized the BlueMoon exploit kit to execute a command that would download an executable named "chrome_cleanup.exe" from a bogus domain.

    The executable, which was later identified as part of the CLEANGULP malware family, was built using the Microsoft Visual C Compiler. The malware supported a range of capabilities, including running a command, listing running processes, uploading and downloading files, and executing a beacon object file (BOF). Interestingly, the malware has been found to use a hard-coded domain named "thecovnresation[.]com" for command-and-control (C2) over HTTP, which is an attempt to mimic the domain of "theconversation[.]com," a non-profit media outlet known for publishing academic research, analysis, and commentary.

    The researchers at Volexity believe that the widespread adoption of the CLEANGULP malware across multiple threat actors suggests a coordinated effort within the Chinese CNE community. According to Volexity, the core kit was likely shared, customized, and weaponized by multiple groups, which would explain the seemingly widespread adoption of the malware. However, the researchers noted that the activity reported so far reflects only two organizations' observations, and the full scope and impact of the attacks are likely far broader.

    The implications of this coordinated cyberattack are significant, as it highlights the evolving nature of the threat landscape and the need for organizations to stay vigilant and proactive in defending against sophisticated attacks. The use of zero-day exploits and coordinated attacks by Chinese threat actors underscores the importance of robust cybersecurity measures, including regular software updates, patch management, and employee education.

    In conclusion, the coordinated cyberattack involving the CLEANGULP malware and the exploitation of a zero-day chain in Google Chrome and Microsoft Windows serves as a stark reminder of the ongoing threat landscape and the need for organizations to remain vigilant and proactive in defending against sophisticated attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Coordinated-Chinese-Cyberattacks-A-Zero-Day-Exploitation-Chain-Deploying-the-CLEANGULP-Malware-ehn.shtml

  • https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85046

  • https://www.cvedetails.com/cve/CVE-2026-85046/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-87491

  • https://www.cvedetails.com/cve/CVE-2026-87491/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85880

  • https://www.cvedetails.com/cve/CVE-2026-85880/


  • Published: Wed Sep 23 05:04:16 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us