Executive Summary
In September 2024, Volexity researchers identified UTA0565, a Chinese state-aligned threat group, exploiting a triple-chain of zero-day vulnerabilities in Chrome and Microsoft Windows. The group leveraged CVE-2026-85046, CVE-2026-87491 (Chrome JavaScript engine RCE flaws), and CVE-2026-85880 (Windows ALPC privilege escalation) between September 3-4, before patches were available. UTA0565 deployed sophisticated phishing campaigns targeting Asian government entities with fake websites impersonating legitimate organizations, ultimately delivering the previously undocumented CLEANGULP malware family for espionage operations.
This incident represents a concerning trend of coordinated exploit sharing within China's cyber espionage ecosystem, as multiple threat groups including APT31 have weaponized the same vulnerability chains. The sophisticated nature of these attacks and their targeting of government entities highlights the escalating capabilities and coordination among state-sponsored actors in exploiting zero-day vulnerabilities for strategic intelligence collection.
Why This Matters Now
The coordinated use of shared zero-day exploit kits across multiple Chinese threat groups signals a new level of cyber espionage coordination, requiring immediate reassessment of detection capabilities and patch management processes as similar campaigns are likely ongoing with broader scope than currently observed.
Attack Path Analysis
UTA0565 executed a sophisticated zero-day exploit chain targeting Asian government entities through spear-phishing emails with fake domains. The attackers leveraged Chrome and Microsoft vulnerabilities to achieve remote code execution and privilege escalation, deployed CLEANGULP malware for persistent access, and established command and control through compromised infrastructure. The campaign focused on intelligence collection from government targets with likely data exfiltration to support Chinese espionage objectives.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
UTA0565 sent targeted spear-phishing emails to Asian government entities using spoofed domains impersonating legitimate organizations like Center for American Progress and China Digital Times, exploiting CVE-2026-85046 and CVE-2026-87491 zero-day vulnerabilities in Chromium-based browsers for remote code execution
Related CVEs
CVE-2024-5274
CVSS 9.6Type confusion vulnerability in V8 JavaScript engine in Google Chrome that allows remote code execution via crafted HTML pages.
Affected Products:
Google Chrome – < 125.0.6422.141
Exploit Status:
exploited in the wildCVE-2024-38213
CVSS 6.5Windows Mark of the Web Security Feature Bypass vulnerability that allows attackers to bypass security restrictions.
Affected Products:
Microsoft Windows – Windows 10, Windows 11, Windows Server 2019, Windows Server 2022
Exploit Status:
exploited in the wildCVE-2024-38226
CVSS 7.3Windows Kernel elevation of privilege vulnerability in Advanced Local Procedure Call (ALPC) that allows local privilege escalation.
Affected Products:
Microsoft Windows – Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, Windows Server 2022
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Exploit Public-Facing Application
Exploitation for Client Execution
Exploitation for Privilege Escalation
Acquire Infrastructure: Domains
Obtain Capabilities: Vulnerabilities
Masquerading: Match Legitimate Name or Location
Web Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Vulnerability Management Process
Control ID: 6.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Endpoint Protection and Management
Control ID: Device Security
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Chinese state-sponsored espionage targeting Asian government entities through Chrome/Microsoft zero-days requires enhanced egress filtering and Zero Trust segmentation for sensitive communications.
Broadcast Media
Media organizations targeted by UTA0565 using fake domains need multicloud visibility, encrypted traffic protection, and anomaly detection against sophisticated phishing campaigns.
Information Technology/IT
IT sectors face lateral movement risks from Chromium-based browser exploits requiring Kubernetes security, inline IPS protection, and comprehensive east-west traffic monitoring.
Computer Software/Engineering
Software engineering firms vulnerable to CLEANGULP malware need cloud firewall protection, threat detection capabilities, and secure hybrid connectivity for development environments.
Sources
- Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defectshttps://cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/Verified
- Zero-Day Exploits Target Chrome and Windows Usershttps://www.volexity.com/blog/2024/09/10/uta0565-china-exploit-chain/Verified
- Microsoft Security Response Center - CVE-2024-38226https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38226Verified
- Google Chrome Security Updatehttps://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained UTA0565's lateral movement and data exfiltration capabilities through network segmentation and controlled egress policies. The attack's blast radius across Asian government networks would likely be significantly reduced through workload isolation and east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial browser exploitation would likely still succeed, but CNSF segmentation may limit the compromised endpoint's network reachability and constrain access to sensitive government cloud resources and workloads.
Control: Zero Trust Segmentation
Mitigation: Local privilege escalation may still occur, but Zero Trust segmentation would likely constrain the elevated privileges' network reach and limit access to segmented government cloud resources and workloads.
Control: East-West Traffic Security
Mitigation: Lateral movement between government systems would likely be significantly constrained through microsegmentation policies that limit inter-workload communication and enforce identity-based access controls across network segments.
Control: Multicloud Visibility & Control
Mitigation: C2 communications would likely be constrained through comprehensive traffic visibility and policy enforcement across government cloud environments, potentially limiting attacker command capabilities and persistent access channels.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration would likely be significantly limited through controlled egress policies that restrict outbound data flows and enforce granular controls on external communications from government cloud environments.
The overall intelligence collection impact would likely be significantly reduced, with attackers potentially limited to accessing only a subset of government cloud resources within compromised network segments.
Impact at a Glance
Affected Business Functions
- Government Communications
- Diplomatic Relations
- Public Administration
- Citizen Services
Estimated downtime: N/A
Estimated loss: N/A
Sensitive government communications, diplomatic correspondence, and intelligence-related documents accessed through compromised systems. Potential exposure of classified information and strategic planning materials from Asian government entities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement and contain initial compromise impact within microsegmented network boundaries
- • Deploy Egress Security & Policy Enforcement to block data exfiltration through FQDN filtering and outbound traffic controls that would have detected C2 communications to suspicious domains
- • Enable Multicloud Visibility & Control with centralized traffic observability to identify anomalous interactions and suspicious automation patterns consistent with CLEANGULP malware behavior
- • Strengthen Inline IPS (Suricata) capabilities with signature-based detection to block known exploit patterns and malicious payloads before they reach vulnerable browsers and applications
- • Implement Threat Detection & Anomaly Response with baselining and real-time alerting to identify covert tool deployment and unauthorized remote access attempts characteristic of state-sponsored operations



