Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Target Chrome-Windows with Zero-Day Exploits

Chinese Hackers Target Chrome-Windows with Zero-Day Exploits

Posted on September 23, 2026 By CWS

In a recent cybersecurity incident, a group of hackers identified as UTA0565 has been found exploiting a series of zero-day vulnerabilities in Google Chrome and Microsoft Windows. These attacks were first detected on September 3 and 4, 2026, and involve a sophisticated chain of exploits targeting high-profile applications.

Details of the Exploit Chain

The hackers utilized two specific vulnerabilities in Chrome, identified as CVE-2026-85046 and CVE-2026-87491, along with a weakness in the Windows Advanced Local Procedure Call, noted as CVE-2026-85880. This combination allowed the attackers to bypass browser security measures and execute remote code, posing significant risks to users.

According to researchers Damien Cash and Tom Lancaster from Volexity, UTA0565 employed deceptive tactics by posing as legitimate entities like media organizations and NGOs. This strategy involved creating fake websites to lure victims into their trap.

Targeted Phishing Campaigns

One notable campaign orchestrated by UTA0565 targeted government bodies in Asia. The attackers sent phishing emails in both Chinese and English, encouraging recipients to support Hong Kong activist Chow Hang-tung, who was recently sentenced to prison. The emails impersonated the Center for American Progress and directed users to fraudulent websites resembling legitimate ones.

The malicious sites loaded hidden HTML elements, deploying an exploit kit that combined the identified vulnerabilities to deliver a payload known as CLEANGULP. This malware was crafted using Microsoft’s Visual C Compiler and featured capabilities such as command execution and file manipulation.

Implications and Broader Impact

The CLEANGULP malware communicated with a hard-coded command-and-control domain, a clever imitation of a reputable media outlet’s domain, indicating a broader strategy to evade detection. Volexity suggests that this attack might be part of a larger coordinated effort within the Chinese cyber espionage community, as the toolkit appears to have been shared and adapted by multiple groups.

While the current findings are based on limited observations, the potential reach and impact of these attacks are likely extensive, emphasizing the need for heightened vigilance in cybersecurity practices.

As cybersecurity threats continue to evolve, it is crucial for individuals and organizations to stay informed and take proactive measures to protect their digital assets against such sophisticated attacks.

The Hacker News Tags:Chinese hackers, Chrome vulnerability, CLEANGULP malware, CVE-2026-85046, CVE-2026-85880, CVE-2026-87491, cyber threats, Cybersecurity, phishing attacks, Windows exploit, zero-day

Post navigation

Previous Post: Leading Decentralized Identity Solutions for 2026
Next Post: ShinyHunters Allegedly Breach FBI Systems, Demand Retraction

Related Posts

EtherRAT Uses GitHub Facades to Target Admin Accounts EtherRAT Uses GitHub Facades to Target Admin Accounts The Hacker News
Ghost Phishing Unveils Security Gaps in Email Protection Ghost Phishing Unveils Security Gaps in Email Protection The Hacker News
Adobe Tackles Major Security Flaws in ColdFusion and Campaign Adobe Tackles Major Security Flaws in ColdFusion and Campaign The Hacker News
Anthropic Launches Claude AI for Healthcare with Secure Health Record Access Anthropic Launches Claude AI for Healthcare with Secure Health Record Access The Hacker News
Lazarus Group Targets Finance with RemotePE Malware Lazarus Group Targets Finance with RemotePE Malware The Hacker News
CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious Streaming App Threatens Android Devices
  • Chrome 154 Secures Users with 108 Vulnerability Fixes
  • AI-Powered Cyberattacks: New Era of Fraud and Trust Misuse
  • ShinyHunters Allegedly Breach FBI Systems, Demand Retraction
  • Chinese Hackers Target Chrome-Windows with Zero-Day Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious Streaming App Threatens Android Devices
  • Chrome 154 Secures Users with 108 Vulnerability Fixes
  • AI-Powered Cyberattacks: New Era of Fraud and Trust Misuse
  • ShinyHunters Allegedly Breach FBI Systems, Demand Retraction
  • Chinese Hackers Target Chrome-Windows with Zero-Day Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark