Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-85046 & CVE-2026-87491 Vulnerabilities

Chinese Threat Actor Exploits Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

China-linked UTA0565 exploited Chrome and Windows zero-days through fake websites to deploy CLEANGULP, a new backdoor supporting commands, file theft and BOF execution.

Cybersecurity researchers have identified a China-linked threat actor exploiting a chain of Google Chrome and Microsoft Windows zero-day vulnerabilities to compromise targets and deploy a previously undocumented backdoor called CLEANGULP.

Volexity tracks the threat actor as UTA0565 and observed the attacks on September 3 and 4, 2026, when the vulnerabilities were still unpatched. The campaign targeted Asian government entities using phishing emails and fake websites impersonating legitimate media and non-governmental organizations.

Three Vulnerabilities Chained Together

The attackers used the BlueMoon exploit kit, which combines three vulnerabilities:

CVE Component Role
CVE-2026-85046 Chrome V8 Initial browser code execution
CVE-2026-87491 Chrome V8 Sandbox escape
CVE-2026-85880 Windows ALPC Privilege escalation

Together, the vulnerabilities allowed attackers to move from malicious browser content to code execution outside Chrome's sandbox and ultimately gain elevated access on Windows.

Fake Websites Used to Trigger BlueMoon

UTA0565 sent phishing emails in Chinese and English that directed victims to attacker-controlled domains designed to resemble legitimate organizations, including China Digital Times and the Center for American Progress.

The fraudulent pages loaded a hidden config.html element that triggered the BlueMoon exploit chain.

The attack can be summarized as:

Phishing Email → Fake Website → Hidden BlueMoon Exploit → Chrome RCE → Sandbox Escape → Windows Privilege Escalation → CLEANGULP

Following successful exploitation, shellcode downloaded a file named:

chrome_cleanup.exe

Despite its legitimate-looking name, the executable contained the new CLEANGULP malware.

What Is CLEANGULP?

CLEANGULP is a custom Windows backdoor written in C and compiled using Microsoft Visual C Compiler. Volexity found that the malware uses control-flow flattening and indirect calls to make analysis more difficult.

Its identified commands include:

  • shell – Execute commands
  • ps – List running processes
  • upload – Upload files
  • download – Download files
  • bof – Execute Beacon Object Files

CLEANGULP installs itself as:

%LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe

and establishes persistence using a scheduled task named:

MicrosoftIME

This gives attackers a persistent platform for remote command execution, file theft and deployment of additional capabilities.

C2 Domain Mimics Legitimate Media Site

The analyzed CLEANGULP sample communicates over HTTP with:

thecovnresation[.]com

The domain appears deliberately designed to resemble theconversation.com, the legitimate media and academic-analysis website.

After execution, CLEANGULP sends an initial registration request to the command-and-control server before waiting for attacker instructions.

BlueMoon Is Being Shared Across Multiple Threat Actors

UTA0565 is not the only group observed using BlueMoon.

Proofpoint previously identified several espionage-focused threat clusters using the same underlying exploit chain within a short period, including APT31 and other China-aligned or unattributed clusters. Different groups modified the delivery infrastructure and final malware while retaining the same core Chrome-Windows exploit chain.

Volexity assesses that this pattern suggests the exploit kit may have been shared and customized across multiple actors within the Chinese cyberespionage ecosystem. The exact mechanism through which the different groups obtained BlueMoon remains unknown.

What Security Teams Should Monitor

Organizations should ensure Chrome, Chromium-based browsers and Windows systems are fully updated and investigate indicators such as:

  • Unexpected chrome.exe child processes
  • cmd.exe and curl.exe launched through browser activity
  • chrome_cleanup.exe
  • %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe
  • Scheduled task named MicrosoftIME
  • Connections to thecovnresation[.]com
  • Unexpected BOF execution or post-exploitation activity
  • Users visiting domains imitating legitimate media or NGO websites

Patching prevents exploitation of the vulnerabilities but does not remove malware or persistence already installed on previously compromised systems.

Security Takeaway

The UTA0565 campaign demonstrates how a sophisticated browser-to-OS exploit chain can turn a visit to a convincing fake website into a full Windows compromise:

Fake Website → Chrome Zero-Day → Sandbox Escape → Windows Zero-Day → CLEANGULP Backdoor

The broader concern is the apparent reuse of the BlueMoon exploit framework across multiple threat clusters, allowing different operators to deploy their own malware using the same underlying exploit chain.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.