Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Use Fake Websites for Chrome and Windows Exploits

Hackers Use Fake Websites for Chrome and Windows Exploits

Posted on September 22, 2026 By CWS

Recent cyber activities have revealed a sophisticated campaign by hackers who are creating replicas of legitimate websites to exploit vulnerabilities in both Google Chrome and Microsoft Windows. This method allows them to quietly infiltrate victims’ systems, turning a simple website visit into a full-scale system compromise.

Phishing Emails and Zero-Day Exploits

On September 3 and 4, cyber attackers utilized targeted phishing emails combined with previously unknown vulnerabilities in Chrome and Windows. These emails, directed at Asian government agencies, contained Chinese-language content referencing jailed Hong Kong activist Chow Hang-tung. Another lure impersonated content from the Center for American Progress. This campaign, identified by analysts at Volexity as work from a China-linked group UTA0565, aimed at strategic espionage rather than widespread disruption.

Volexity’s report, shared with Cyber Security News, highlighted the group’s use of an established exploit kit, which was modified to suit their specific goals. The ability of these phishing pages to closely mimic authentic websites shows the ongoing threat they pose to even the most vigilant internet users.

Imitating Trusted Websites

The phishing attacks involved directing victims to domains controlled by the attackers that mimicked real websites. For instance, one fraudulent site mirrored China Digital Times, while another imitated the Center for American Progress. These sites contained hidden iframes that executed malicious code without altering the visible content to users.

Exploiting vulnerabilities CVE-2026-85046 and CVE-2026-87491 in Chrome, along with CVE-2026-85880 in Windows, the attackers managed to escalate privileges within the system. This exploit chain, detailed in the BlueMoon report, demonstrates how attackers can transition from browser-level access to deeper system control.

Introducing CLEANGULP Malware

The attack introduced a new malware family named CLEANGULP, which remains heavily obfuscated to hinder investigation. It installs under a name resembling Microsoft software and sets a scheduled task for persistence. Once operational, it can execute commands, manage files, and communicate with a command server using encrypted messages over HTTP.

This malware uses typo-squatted domains to appear legitimate, blending its activity with normal web traffic. To counter such threats, administrators are advised to monitor for indicators of compromise (IoCs), review logs, and apply security updates promptly.

In summary, this campaign underscores the critical need for organizations to maintain up-to-date security patches and educate staff on verifying unexpected emails. Continued vigilance and proactive measures are essential to safeguarding against such sophisticated cyber threats.

Cyber Security News Tags:Chrome exploits, cyber attack, cyber espionage, Cybersecurity, digital security, Hacking, internet security, Malware, Phishing, phishing scams, security patches, Windows vulnerabilities, zero-day exploits

Post navigation

Previous Post: OT Network Segmentation Lacks Full Isolation: Study
Next Post: AI Agents Redefine Lateral Movement in Security

Related Posts

GitLab Urges Update to Fix Critical Security Flaws GitLab Urges Update to Fix Critical Security Flaws Cyber Security News
Windows 11 Vulnerabilities Expose MFA Flaws Windows 11 Vulnerabilities Expose MFA Flaws Cyber Security News
Critical Redis Flaws Expose Systems to Remote Attacks Critical Redis Flaws Expose Systems to Remote Attacks Cyber Security News
Gemini CLI to Your Kali Linux Terminal To Automate Penetration Testing Tasks Gemini CLI to Your Kali Linux Terminal To Automate Penetration Testing Tasks Cyber Security News
Ollama Vulnerability Exposes Servers to Data Leaks Ollama Vulnerability Exposes Servers to Data Leaks Cyber Security News
Citrix NetScaler Targeted by Sophisticated Scanning Campaign Citrix NetScaler Targeted by Sophisticated Scanning Campaign Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Researcher Reveals New Microsoft Defender Exploit
  • AI Agents Redefine Lateral Movement in Security
  • Hackers Use Fake Websites for Chrome and Windows Exploits
  • OT Network Segmentation Lacks Full Isolation: Study
  • DORA’s Impact on SOC Visibility: Key Insights

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Researcher Reveals New Microsoft Defender Exploit
  • AI Agents Redefine Lateral Movement in Security
  • Hackers Use Fake Websites for Chrome and Windows Exploits
  • OT Network Segmentation Lacks Full Isolation: Study
  • DORA’s Impact on SOC Visibility: Key Insights

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark