importantSYS.SOURCE: The Hacker News• 2026-09-23T13:59:24+05:30
Chinese Threat Actors Exploit Chrome-Windows Zero-Day Chain for CLEANGULP Malware Deployment
Chinese threat actor UTA0565 exploited a Chrome-Windows zero-day chain (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) through phishing campaigns to deploy CLEANGULP malware, which uses a spoofed domain to mimic legitimate media outlets for command-and-control communications.
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.
The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break
*** END OF TRANSMISSION ***