A Chinese crew turned three unpatched browser bugs into a backdoor

Volexity has linked a China-aligned group to a three-bug Chrome and Windows chain that ran before either vendor shipped a patch.

CSBadmin
2 Min Read

Volexity has tied a China-aligned group it calls UTA0565 to a triple zero-day chain that ran on Chrome and Windows before either vendor shipped a fix.

The attacks landed on September 3 and 4, 2026. Victims clicked spoofed links that pulled in a hidden iframe, which loaded the BlueMoon exploit kit. Three bugs did the work: CVE-2026-85046 and CVE-2026-87491 in the Chromium JavaScript engine, plus CVE-2026-85880, a privilege escalation flaw Microsoft disclosed on September 8 in Windows Advanced Local Procedure Call. Together they break out of the browser sandbox and reach remote code execution, after which a payload named chrome_cleanup.exe drops CLEANGULP.

The malware, built with Microsoft’s Visual C compiler, is unremarkable by design: shell, process listing, upload, download and a beacon object file runner. Its command channel points at thecovnresation[.]com, a near-miss of theconversation[.]com.

The social engineering is the interesting part. Fake sites impersonated the Center for American Progress and China Digital Times, and phishing mail pressed Asian government targets to back jailed Hong Kong activist Chow Hang-tung. Volexity says the group also ran decoy campaigns built around media outlets, a halal restaurant directory and corporate training firms.

Proofpoint previously attributed the same kit to APT31, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket, hinting at a shared core among Chinese operators. Volexity warns that only two organizations have reported sightings, so the real reach is probably wider. Patch Chrome and Windows now, and treat unsolicited activist or policy lures as a delivery vector.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.