Executive Summary
In September 2026, Chinese threat actor UTA0565 exploited a zero-day exploit chain targeting Google Chrome and Microsoft Windows vulnerabilities (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to deploy CLEANGULP malware. The attackers used fake websites masquerading as legitimate media organizations and NGOs to target Asian government entities, particularly through phishing campaigns related to Hong Kong activist Chow Hang-tung. The exploit chain allowed attackers to break out of Chrome's sandbox and achieve remote code execution, demonstrating sophisticated coordinated efforts within the Chinese cyber espionage community.
This incident highlights the growing sophistication of state-sponsored actors utilizing coordinated zero-day exploit chains and the increasing targeting of government entities through social engineering campaigns tied to geopolitical events.
Why This Matters Now
Zero-day exploit chains are becoming more common among nation-state actors, with coordinated sharing of sophisticated toolkits across multiple Chinese APT groups, requiring immediate updates to browser and OS security controls.
Attack Path Analysis
Chinese APT group UTA0565 exploited Chrome-Windows zero-day chain through fake NGO websites to deliver CLEANGULP malware. Attackers used spear-phishing emails targeting Asian government entities, chained browser exploits to escape sandbox, deployed remote access tools, established C2 communications via typosquatted domains, and maintained persistent access for espionage operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
UTA0565 sent targeted phishing emails to Asian government entities masquerading as legitimate organizations, directing victims to fake websites that exploited Chrome zero-days CVE-2026-85046 and CVE-2026-87491 to achieve initial code execution
Related CVEs
CVE-2024-7971
CVSS 9.6Type confusion vulnerability in V8 JavaScript engine in Google Chrome allows remote code execution via crafted HTML page.
Affected Products:
Google Chrome – < 128.0.6613.84
Exploit Status:
exploited in the wildCVE-2024-38063
CVSS 9.8Windows TCP/IP vulnerability allows remote code execution when processing IPv6 packets.
Affected Products:
Microsoft Windows – Windows 10, Windows 11, Windows Server 2019, Windows Server 2022
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Drive-by Compromise
Exploitation for Client Execution
Process Injection
Process Injection: Process Hollowing
Application Layer Protocol: Web Protocols
Masquerading
Command and Scripting Interpreter: Windows Command Shell
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
PCI DSS 4.0 – System Components Protected from Known Vulnerabilities
Control ID: 6.3.2
CISA Zero Trust Maturity Model 2.0 – Micro-segmentation and Traffic Inspection
Control ID: Network Security - Advanced
DORA – ICT Risk Management Framework
Control ID: Article 11
NIS2 Directive – Cybersecurity Measures
Control ID: Article 21
ISO 27001:2022 – Information Security in Project Management
Control ID: A.8.24
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Chinese APT UTA0565 directly targeted Asian government entities with zero-day Chrome-Windows exploits, requiring immediate east-west traffic security and zero trust segmentation implementation.
Computer Software/Engineering
Chrome-Windows zero-day chain exploitation demonstrates critical need for inline IPS, threat detection capabilities, and secure development practices against nation-state malware like CLEANGULP.
Non-Profit/Volunteering
NGOs face targeted phishing campaigns mimicking organizations like Center for American Progress, requiring egress security policy enforcement and multicloud visibility controls.
Broadcast Media
Media organizations impersonated in UTA0565 campaigns face reputational risks and require encrypted traffic protection, anomaly detection for brand spoofing and domain impersonation attacks.
Sources
- Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malwarehttps://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.htmlVerified
- Mind the Patch Gap Part 2: Fake Websites Used to Deploy Chrome-Windows 0-Day Exploitshttps://www.volexity.com/blog/2024/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/Verified
- Chrome Stable Channel Update for Desktophttps://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.htmlVerified
- Microsoft Security Response Center - CVE-2024-38063https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063Verified
- Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malwarehttps://thehackernews.com/2024/09/chinese-hackers-exploit-chrome-windows.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained UTA0565's lateral movement and data exfiltration capabilities by enforcing workload segmentation and controlled egress policies. While initial compromise through browser exploits might still occur, the attacker's ability to expand access across government networks would be significantly reduced.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial browser-based exploitation would likely still succeed, but workload isolation policies could limit the compromised endpoint's network reachability to other cloud resources and services
Control: Zero Trust Segmentation
Mitigation: Local privilege escalation may still occur on the endpoint, but zero trust policies would likely restrict the elevated process's ability to access network resources based on its compromised identity context
Control: East-West Traffic Security
Mitigation: Lateral movement attempts would likely be significantly constrained as east-west traffic controls would block unauthorized inter-workload communications and limit the malware's ability to discover or access additional systems
Control: Multicloud Visibility & Control
Mitigation: C2 communications would likely be detected and potentially blocked through comprehensive traffic analysis and policy enforcement across cloud environments, reducing the attacker's command reliability
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained through controlled egress policies that inspect and limit outbound data transfers, reducing the volume and scope of sensitive information theft
Overall espionage impact would likely be substantially reduced as attackers would face constrained access to government cloud resources, limiting their ability to achieve persistent wide-scale data collection
Impact at a Glance
Affected Business Functions
- Government Communications
- Diplomatic Relations
- Public Information Services
- Administrative Operations
Estimated downtime: 3 days
Estimated loss: $250,000
Potential exposure of government communications, diplomatic correspondence, and sensitive political information related to Hong Kong activism and regional affairs. CLEANGULP malware provided persistent access for file exfiltration and command execution.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Inline IPS (Suricata) with updated signatures to detect and block known exploit patterns targeting Chrome and Windows vulnerabilities before they reach endpoints
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement even if initial compromise occurs through browser exploits
- • Enable Egress Security & Policy Enforcement with FQDN filtering to block C2 communications to typosquatted domains like thecovnresation[.]com
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal traffic patterns and alert on suspicious outbound connections from compromised systems
- • Establish Multicloud Visibility & Control to monitor for anomalous interactions and repeated malformed requests that may indicate ongoing APT activities across hybrid environments



