Chinese State Hackers Weaponize Chrome-Windows Zero-Day Chain for CLEANGULP Malware

4 min read
Source: The Hacker News
Chinese State Hackers Weaponize Chrome-Windows Zero-Day Chain for CLEANGULP Malware
Photo: The Hacker News
TL;DR

A Chinese state-aligned threat group known as UTA0565 exploited a chain of three zero-day vulnerabilities in Google Chrome and Microsoft Windows to deploy new malware dubbed CLEANGULP. The attacks, detected on September 3 and 4, 2026, occurred before official patches were released, leveraging fake websites mimicking trusted organizations to deliver the payload. The exploit chain, named BlueMoon, combines two Chrome V8 engine flaws and one Windows privilege escalation bug to achieve remote code execution. Volexity researchers noted that this widespread adoption across multiple Chinese groups suggests a coordinated effort within the Chinese computer network exploitation community, with the core kit likely shared and customized by various actors.

Key points

  • Threat actor UTA0565 exploited CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escape browser sandboxes and execute code.
  • The CLEANGULP malware, built with Microsoft Visual C Compiler, supports shell access, file transfer, and beacon object file execution.
  • Attacks used fake websites mimicking the Center for American Progress and China Digital Times to deceive victims, including Asian government entities.
  • Volexity reports indicate the exploit kit was shared across multiple Chinese state-aligned groups, suggesting coordinated activity within the CNE community.
  • Google and Microsoft have since patched the vulnerabilities, but experts warn that the gap between public code fixes and user updates remains a security risk.

Background

This incident follows a series of zero-day exploits in Chrome and Windows throughout 2026. In September 2026, Google patched CVE-2026-85046 and CVE-2026-87491, which had been actively exploited in the wild. Earlier in the month, other Chinese-linked groups, such as UTA0560 and APT31, used the same BlueMoon exploit chain to deploy different malware families like GRIMWEDGE and LONGTALE. The current CLEANGULP campaign represents a further evolution of these tactics, with attackers using more sophisticated fake websites to reduce user suspicion. The broader context includes a shift by Google to a two-week Chrome release cycle, aimed at reducing the window between public code fixes and user updates, though experts note this does not fully eliminate the risk of N-day exploits.

How outlets are covering it

Volexity emphasized the coordinated nature of the attacks, noting that the widespread adoption of the BlueMoon kit across multiple Chinese threat actors suggests a shared and customized core kit. Cybernews highlighted the 'patch gap' issue, where attackers could scrutinize public code fixes before they reached users, leading to a four-week window of vulnerability. CyberScoop focused on the technical improvements in UTA0565's campaigns, noting the use of real content from legitimate websites as decoy material to reduce user suspicion. All sources agree on the severity of the zero-day chain and the need for prompt patching, but they differ in emphasis: Volexity on coordination, Cybernews on the patch gap, and CyberScoop on the sophistication of the deception tactics.

Why it matters

The exploitation of zero-day vulnerabilities in widely used software like Chrome and Windows poses a significant risk to global cybersecurity. The coordinated effort by Chinese state-aligned groups to share and customize exploit kits indicates a sophisticated and organized threat landscape. The use of fake websites mimicking trusted organizations to deliver malware highlights the evolving tactics of attackers, making it harder for users to distinguish between legitimate and malicious content. This incident underscores the importance of prompt patching and the need for improved security measures to reduce the window between public code fixes and user updates.

What to watch

Users are urged to promptly patch Chrome, Windows, and any other software to mitigate the risk of exploitation. Google has shortened its Chrome release cycle to two weeks to reduce the patch gap, but experts warn that this does not fully eliminate the risk of N-day exploits. Security researchers will continue to monitor for further exploitation of the BlueMoon kit and other zero-day vulnerabilities. Organizations should also enhance their security measures, including using AI-driven tools to detect and respond to threats, and educating users on the risks of clicking suspicious links.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News