Chinese Hackers Exploit Chrome and Windows Zero-Days to Deploy New CLEANGULP Malware
Security researchers at Volexity have identified a Chinese threat actor, tracked as UTA0565, exploiting a chain of previously unknown vulnerabilities in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) to break out of the browser sandbox and run malicious code on victims' machines. The attacks were detected in early September 2026.
The group used fake websites impersonating media outlets and a non-governmental organisation to lure targets. In one campaign, phishing emails written in Chinese and English urged recipients to support jailed Hong Kong activist Chow Hang-tung, directing them to spoofed sites mimicking China Digital Times and the Center for American Progress. Hidden page elements on these sites triggered the exploit chain, ultimately downloading a file called "chrome_cleanup.exe" containing the CLEANGULP malware, which then communicated with a command server disguised to look like a legitimate media domain.
Volexity believes the exploit kit behind these attacks may be shared among multiple Chinese hacking groups, suggesting the true scale of these attacks is likely much larger than what has been observed so far.