Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Bitget’s $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says

    September 26, 2026

    Stonehenge’s 6-ton altar stone may have traveled from Scotland by glacier

    September 26, 2026

    Netanyahu compared Oct. 7 attack to ’16 9/11s’

    September 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Bitget’s $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says
    • Stonehenge’s 6-ton altar stone may have traveled from Scotland by glacier
    • Netanyahu compared Oct. 7 attack to ’16 9/11s’
    • US court rules against Kalshi, says states can regulate prediction markets | Courts News
    • Special agents blood and urine test results stolen in FBI hack
    • Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
    • Live updates: Bitcoin moves to $84,000, oil slides on latest report of Middle East progress
    • Why Viking museums still can’t escape the warrior myth
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 26, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 23, 2026Zero-Day / Vulnerability

    A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.

    The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser’s sandbox and achieve remote code execution.

    “UTA0565 masqueraded as various entities including media organizations and a non-governmental organization (NGO),” Volexity researchers Damien Cash and Tom Lancaster said in an analysis published this week. “Notably, this threat actor’s campaigns differed from previously documented attacks by using multiple fake websites to deceive victims.”

    One such campaign targeted Asian government entities with Chinese- and English-language phishing emails that urged recipients to support Hong Kong activist Chow Hang-tung and masqueraded as the Center for American Progress (CAP). Chow was sentenced to seven years and three months in prison earlier this month.

    Cybersecurity

    These messages contained spoofed links pointing to “chinadigitaltimes[.]top” and “americanprgoress[.]top,” which replicated the look of China Digital Times and CAP, while loading an additional HTML element via a hidden iframe.

    The HTML element (“config.html”) is said to have used the same BlueMoon exploit kit combining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, with the final “pp” shellcode downloading an executable named “chrome_cleanup.exe” from the bogus domain. The payload is a malware family dubbed CLEANGULP, which is built using the Microsoft Visual C Compiler.

    It supports the following capabilities –

    • shell, to run a command
    • ps, to list running processes
    • upload, to upload a file
    • download, to download a file
    • bof, to execute a Execution of a beacon object file (BOF)

    Interestingly, CLEANGULP has been found to use a hard-coded domain named “thecovnresation[.]com” for command-and-control (C2) over HTTP, indicating an attempt to mimic “theconversation[.]com,” a non-profit media outlet known for publishing academic research, analysis, and commentary.

    “This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese CNE community, where the core kit was likely shared, customized, and weaponized by multiple groups,” Volexity said. “The activity reported so far reflects only two organizations’ observations; the full scope and impact are likely far broader.”

    chain Chinese ChromeWindows CLEANGULP Deploy exploit hackers Malware ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    To tackle environmental crime, track profits through the whole supply chain (commentary)

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Bitget’s $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says

    September 26, 2026

    Stonehenge’s 6-ton altar stone may have traveled from Scotland by glacier

    September 26, 2026

    Netanyahu compared Oct. 7 attack to ’16 9/11s’

    September 26, 2026

    US court rules against Kalshi, says states can regulate prediction markets | Courts News

    September 26, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Bitget’s $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says

    September 26, 2026

    Stonehenge’s 6-ton altar stone may have traveled from Scotland by glacier

    September 26, 2026

    Netanyahu compared Oct. 7 attack to ’16 9/11s’

    September 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.