Recent cyber activities have revealed a sophisticated campaign by hackers who are creating replicas of legitimate websites to exploit vulnerabilities in both Google Chrome and Microsoft Windows. This method allows them to quietly infiltrate victims’ systems, turning a simple website visit into a full-scale system compromise.
Phishing Emails and Zero-Day Exploits
On September 3 and 4, cyber attackers utilized targeted phishing emails combined with previously unknown vulnerabilities in Chrome and Windows. These emails, directed at Asian government agencies, contained Chinese-language content referencing jailed Hong Kong activist Chow Hang-tung. Another lure impersonated content from the Center for American Progress. This campaign, identified by analysts at Volexity as work from a China-linked group UTA0565, aimed at strategic espionage rather than widespread disruption.
Volexity’s report, shared with Cyber Security News, highlighted the group’s use of an established exploit kit, which was modified to suit their specific goals. The ability of these phishing pages to closely mimic authentic websites shows the ongoing threat they pose to even the most vigilant internet users.
Imitating Trusted Websites
The phishing attacks involved directing victims to domains controlled by the attackers that mimicked real websites. For instance, one fraudulent site mirrored China Digital Times, while another imitated the Center for American Progress. These sites contained hidden iframes that executed malicious code without altering the visible content to users.
Exploiting vulnerabilities CVE-2026-85046 and CVE-2026-87491 in Chrome, along with CVE-2026-85880 in Windows, the attackers managed to escalate privileges within the system. This exploit chain, detailed in the BlueMoon report, demonstrates how attackers can transition from browser-level access to deeper system control.
Introducing CLEANGULP Malware
The attack introduced a new malware family named CLEANGULP, which remains heavily obfuscated to hinder investigation. It installs under a name resembling Microsoft software and sets a scheduled task for persistence. Once operational, it can execute commands, manage files, and communicate with a command server using encrypted messages over HTTP.
This malware uses typo-squatted domains to appear legitimate, blending its activity with normal web traffic. To counter such threats, administrators are advised to monitor for indicators of compromise (IoCs), review logs, and apply security updates promptly.
In summary, this campaign underscores the critical need for organizations to maintain up-to-date security patches and educate staff on verifying unexpected emails. Continued vigilance and proactive measures are essential to safeguarding against such sophisticated cyber threats.
