Threat Intelligence

Chinese Hackers Exploit Chrome and Windows Zero-Days to Deploy New CLEANGULP Malware

The Hacker News · 23 Sept 2026
Key Takeaway Ensure Chrome and Windows updates are applied as soon as patches for these vulnerabilities are released, and train staff to be cautious of unsolicited links, even from seemingly legitimate news or advocacy sites.

Security researchers at Volexity have identified a Chinese threat actor, tracked as UTA0565, exploiting a chain of previously unknown vulnerabilities in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) to break out of the browser sandbox and run malicious code on victims' machines. The attacks were detected in early September 2026.

The group used fake websites impersonating media outlets and a non-governmental organisation to lure targets. In one campaign, phishing emails written in Chinese and English urged recipients to support jailed Hong Kong activist Chow Hang-tung, directing them to spoofed sites mimicking China Digital Times and the Center for American Progress. Hidden page elements on these sites triggered the exploit chain, ultimately downloading a file called "chrome_cleanup.exe" containing the CLEANGULP malware, which then communicated with a command server disguised to look like a legitimate media domain.

Volexity believes the exploit kit behind these attacks may be shared among multiple Chinese hacking groups, suggesting the true scale of these attacks is likely much larger than what has been observed so far.

zero-day Chrome vulnerability Chinese APT malware Windows security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.