In a recent cybersecurity incident, a group of hackers identified as UTA0565 has been found exploiting a series of zero-day vulnerabilities in Google Chrome and Microsoft Windows. These attacks were first detected on September 3 and 4, 2026, and involve a sophisticated chain of exploits targeting high-profile applications.
Details of the Exploit Chain
The hackers utilized two specific vulnerabilities in Chrome, identified as CVE-2026-85046 and CVE-2026-87491, along with a weakness in the Windows Advanced Local Procedure Call, noted as CVE-2026-85880. This combination allowed the attackers to bypass browser security measures and execute remote code, posing significant risks to users.
According to researchers Damien Cash and Tom Lancaster from Volexity, UTA0565 employed deceptive tactics by posing as legitimate entities like media organizations and NGOs. This strategy involved creating fake websites to lure victims into their trap.
Targeted Phishing Campaigns
One notable campaign orchestrated by UTA0565 targeted government bodies in Asia. The attackers sent phishing emails in both Chinese and English, encouraging recipients to support Hong Kong activist Chow Hang-tung, who was recently sentenced to prison. The emails impersonated the Center for American Progress and directed users to fraudulent websites resembling legitimate ones.
The malicious sites loaded hidden HTML elements, deploying an exploit kit that combined the identified vulnerabilities to deliver a payload known as CLEANGULP. This malware was crafted using Microsoft’s Visual C Compiler and featured capabilities such as command execution and file manipulation.
Implications and Broader Impact
The CLEANGULP malware communicated with a hard-coded command-and-control domain, a clever imitation of a reputable media outlet’s domain, indicating a broader strategy to evade detection. Volexity suggests that this attack might be part of a larger coordinated effort within the Chinese cyber espionage community, as the toolkit appears to have been shared and adapted by multiple groups.
While the current findings are based on limited observations, the potential reach and impact of these attacks are likely extensive, emphasizing the need for heightened vigilance in cybersecurity practices.
As cybersecurity threats continue to evolve, it is crucial for individuals and organizations to stay informed and take proactive measures to protect their digital assets against such sophisticated attacks.
