Chinese Threat Actor Exploits Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
China-linked UTA0565 exploited Chrome and Windows zero-days through fake websites to deploy CLEANGULP, a new backdoor supporting commands, file theft and BOF execution.

Cybersecurity researchers have identified a China-linked threat actor exploiting a chain of Google Chrome and Microsoft Windows zero-day vulnerabilities to compromise targets and deploy a previously undocumented backdoor called CLEANGULP.
Volexity tracks the threat actor as UTA0565 and observed the attacks on September 3 and 4, 2026, when the vulnerabilities were still unpatched. The campaign targeted Asian government entities using phishing emails and fake websites impersonating legitimate media and non-governmental organizations.
Three Vulnerabilities Chained Together
The attackers used the BlueMoon exploit kit, which combines three vulnerabilities:
| CVE | Component | Role |
|---|---|---|
| CVE-2026-85046 | Chrome V8 | Initial browser code execution |
| CVE-2026-87491 | Chrome V8 | Sandbox escape |
| CVE-2026-85880 | Windows ALPC | Privilege escalation |
Together, the vulnerabilities allowed attackers to move from malicious browser content to code execution outside Chrome's sandbox and ultimately gain elevated access on Windows.
Fake Websites Used to Trigger BlueMoon
UTA0565 sent phishing emails in Chinese and English that directed victims to attacker-controlled domains designed to resemble legitimate organizations, including China Digital Times and the Center for American Progress.
The fraudulent pages loaded a hidden config.html element that triggered the BlueMoon exploit chain.
The attack can be summarized as:
Phishing Email → Fake Website → Hidden BlueMoon Exploit → Chrome RCE → Sandbox Escape → Windows Privilege Escalation → CLEANGULP
Following successful exploitation, shellcode downloaded a file named:
chrome_cleanup.exe
Despite its legitimate-looking name, the executable contained the new CLEANGULP malware.
What Is CLEANGULP?
CLEANGULP is a custom Windows backdoor written in C and compiled using Microsoft Visual C Compiler. Volexity found that the malware uses control-flow flattening and indirect calls to make analysis more difficult.
Its identified commands include:
shell– Execute commandsps– List running processesupload– Upload filesdownload– Download filesbof– Execute Beacon Object Files
CLEANGULP installs itself as:
%LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe
and establishes persistence using a scheduled task named:
MicrosoftIME
This gives attackers a persistent platform for remote command execution, file theft and deployment of additional capabilities.
C2 Domain Mimics Legitimate Media Site
The analyzed CLEANGULP sample communicates over HTTP with:
thecovnresation[.]com
The domain appears deliberately designed to resemble theconversation.com, the legitimate media and academic-analysis website.
After execution, CLEANGULP sends an initial registration request to the command-and-control server before waiting for attacker instructions.
BlueMoon Is Being Shared Across Multiple Threat Actors
UTA0565 is not the only group observed using BlueMoon.
Proofpoint previously identified several espionage-focused threat clusters using the same underlying exploit chain within a short period, including APT31 and other China-aligned or unattributed clusters. Different groups modified the delivery infrastructure and final malware while retaining the same core Chrome-Windows exploit chain.
Volexity assesses that this pattern suggests the exploit kit may have been shared and customized across multiple actors within the Chinese cyberespionage ecosystem. The exact mechanism through which the different groups obtained BlueMoon remains unknown.
What Security Teams Should Monitor
Organizations should ensure Chrome, Chromium-based browsers and Windows systems are fully updated and investigate indicators such as:
- Unexpected
chrome.exechild processes cmd.exeandcurl.exelaunched through browser activitychrome_cleanup.exe%LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe- Scheduled task named
MicrosoftIME - Connections to
thecovnresation[.]com - Unexpected BOF execution or post-exploitation activity
- Users visiting domains imitating legitimate media or NGO websites
Patching prevents exploitation of the vulnerabilities but does not remove malware or persistence already installed on previously compromised systems.
Security Takeaway
The UTA0565 campaign demonstrates how a sophisticated browser-to-OS exploit chain can turn a visit to a convincing fake website into a full Windows compromise:
Fake Website → Chrome Zero-Day → Sandbox Escape → Windows Zero-Day → CLEANGULP Backdoor
The broader concern is the apparent reuse of the BlueMoon exploit framework across multiple threat clusters, allowing different operators to deploy their own malware using the same underlying exploit chain.
Related reporting
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock ransomware attackers exploit Microsoft SharePoint vulnerabilities to gain initial access, disable security tools and distribute ransomware across critical infrastructure networks.
Apple CoreGraphics Zero-Day PoC Emerges as WhatsApp PDF Checks Raise Delivery Questions
A public PoC for Apple CoreGraphics CVE-2026-86950 demonstrates memory corruption through a malicious PDF, while new WhatsApp PDF protections raise questions about a possible delivery path.
Kiteworks Fixes Critical Vulnerability Discovered During Emergency Shutdown
Kiteworks patched a previously unknown critical vulnerability discovered during a nine-hour precautionary shutdown prompted by intelligence about a potential cyberattack, with no evidence of exploitation.


