UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP Malware
UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046 (TL-2026-2681) is a critical-severity zero-day vulnerability scored CVSS 8.8, first published 2026-09-27. It is attributed to UTA0565 (China) with high confidence, affects Google Chrome, references 3 CVEs (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880), maps to 14 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-2681
- Threat ID
- TL-2026-2681
- Severity
- CRITICAL
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- ZERO_DAY
- First published
- 2026-09-27
- Last reviewed
- 2026-09-27
- Attribution
- UTA0565
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, news - media, ngo
- Target regions
- Asia, North America
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046
Malware and tooling: CLEANGULP
Volexity reports that China-aligned threat group UTA0565 chained two Chrome zero-days with a Windows ALPC privilege-escalation zero-day to compromise targets between September 3-4, 2026, before any of the three CVEs were patched or disclosed, deploying a previously undocumented malware family, CLEANGULP, via phishing emails and spoofed media/NGO websites.
How UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046 works
Between September 3 and 4, 2026, the China-aligned threat group UTA0565 chained two unpatched Google Chrome zero-days (CVE-2026-85046, a V8 type-confusion bug providing arbitrary read/write inside the browser sandbox, and CVE-2026-87491, a V8 out-of-bounds write enabling sandbox escape) with a Windows Advanced Local Procedure Call kernel privilege-escalation zero-day (CVE-2026-85880, rooted in the RtlpCreateServerAcl code path) to fully compromise victim hosts before any of the three vulnerabilities were publicly disclosed or patched.
UTA0565 delivered the chain via phishing emails that linked to a network of spoofed websites impersonating legitimate media and policy organizations, including chinadigitaltimes[.]top (spoofing chinadigitaltimes.net) and americanprgoress[.]top (a typosquat of americanprogress.org), registered between September 2 and 4, 2026 and hosted behind 96.9.125[.]52. Victims who visited a fake site triggered a hidden iframe (config.html) that ran the same web-worker-based, three-stage position-independent exploit chain (host reconnaissance, kernel-mode privilege escalation, browser-process injection) that Volexity had already documented on September 9, 2026 as shared by two other Chinese threat actors, UTA0560 and JungleBamboo (APT31/Violet Typhoon/TA412), against the identical three CVEs. Volexity assesses that the byte-identical shellcode across unrelated operators points to a common exploit developer supplying multiple China-nexus groups during the Chrome/Windows patch gap.
Following successful exploitation, UTA0565 dropped a previously undocumented malware family, CLEANGULP, delivered as chrome_cleanup.exe and installed to %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe, persisting via a scheduled task named "MicrosoftIME." CLEANGULP is a control-flow-flattened, indirect-call-obfuscated backdoor supporting shell command execution, process listing, file upload/download, and Beacon Object File (BOF) execution. It communicates over HTTP POST to /beacon/pre-register on the typosquatted C2 domain thecovnresation[.]com (spoofing theconversation.com), encrypting traffic with AES-256-GCM using a key derived from the SHA-256 hash of a custom Base64 alphabet embedded in the binary.
Google patched CVE-2026-85046 on September 4, 2026 (Chrome 152.0.7977.82/.83) and CVE-2026-87491 on September 8, 2026 (Chrome 153.0.8010.36/.37); Microsoft patched CVE-2026-85880 on September 8, 2026 as part of its September Patch Tuesday. CISA added all three CVEs to its Known Exploited Vulnerabilities catalog. Volexity published its UTA0565-specific findings, including the CLEANGULP attribution, on September 21, 2026.
MITRE ATT&CK techniques used in TL-2026-2681
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Persistence
Privilege Escalation
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Command and Control
T1071 Application Layer Protocol; T1573 Encrypted Channel
Initial Access
Resource Development
Affected products and versions in UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046
- Google — Chrome
Vulnerable versions: < 152.0.7977.82 (CVE-2026-85046)
Fixed in: 152.0.7977.82; 152.0.7977.83 - Google — Chrome
Vulnerable versions: < 153.0.8010.36 (CVE-2026-87491)
Fixed in: 153.0.8010.36; 153.0.8010.37 - Microsoft — Windows
Vulnerable versions: Windows 10 1607; Windows 10 1809; Windows 10 21H2; Windows 10 22H2; Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022
Fixed in: September 2026 cumulative update (CVE-2026-85880)
Remediation for UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046
Patches
- Google Chrome 152.0.7977.82/.83 (fixes CVE-2026-85046)
- Google Chrome 153.0.8010.36/.37 (fixes CVE-2026-87491)
- Microsoft September 2026 Patch Tuesday cumulative update (fixes CVE-2026-85880)
Immediate actions
- Patch Chrome to >=153.0.8010.36/.37 and apply the September 2026 Windows cumulative update to all endpoints immediately
- Block/sinkhole the identified UTA0565 domains (chinadigitaltimes.top, americanprgoress.top, thecovnresation.com, thecovnresation.net, personclouds.com, halal-navi.net, borneobulletins.top) and 96.9.125.52 at the perimeter and DNS resolver
- Hunt for the 'MicrosoftIME' scheduled task and %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe on Windows endpoints
- Hunt for outbound HTTP POST traffic to /beacon/pre-register, especially against typosquatted news/media domains
Workarounds
- Restrict or closely monitor execution from %LOCALAPPDATA%\Microsoft\IME\ pending patch deployment
- Apply CISA BOD 26-04 mitigations per the KEV catalog entries for all three CVEs
Longer-term hardening
- Deploy EDR with behavioral detection for BOF/shellcode execution and process injection into browser processes
- Stand up typosquat/DNS-lookalike monitoring for organizations frequently impersonated in these campaigns (media outlets, policy NGOs, government agencies)
- Reduce patch-gap exposure by tracking upstream Chromium security fixes and staged rollouts ahead of general stable-channel availability
CVEs associated with UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046
Weaknesses (CWE) in UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046
CWE-843, CWE-787, CWE-122, CWE-908
Timeline of UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046
- CVE-2026-85046 (V8 type confusion) is privately reported to the Chromium project, entering the Chromium public source tree ahead of a stable Chrome release and opening the 'patch gap' window the exploit chain would abuse.
- Independent researcher Jihyeon Jeong reports the V8 out-of-bounds write later designated CVE-2026-87491 to Google, earning a $2,500 bug bounty; this bug forms the sandbox-escape stage of the same exploit chain.
- UTA0565 begins registering the spoofed lure domains used in the campaign, including chinadigitaltimes.top, americanprgoress.top, thecovnresation.com/.net, personclouds.com, halal-navi.net, and borneobulletins.top.
- Volexity observes UTA0565 exploiting the still-unpatched Chrome and Windows zero-day chain via spoofed media/NGO websites to deploy the CLEANGULP backdoor against targets.
- Google ships Chrome 152.0.7977.82/.83, fixing CVE-2026-85046; CISA adds the CVE to its Known Exploited Vulnerabilities catalog the same day with an September 18 remediation deadline.
- Google ships Chrome 153.0.8010.36/.37, fixing CVE-2026-87491.
- Microsoft's September 2026 Patch Tuesday fixes CVE-2026-85880 (Windows ALPC heap-based buffer overflow); CISA adds it to KEV with a September 22 remediation deadline for federal agencies.
- Volexity publishes 'Mind the (Patch) Gap,' documenting two other Chinese threat actors, UTA0560 and JungleBamboo (APT31/Violet Typhoon/TA412), independently abusing the identical three-CVE exploit chain; CISA adds CVE-2026-87491 to KEV.
- Volexity publishes 'Mind the (Patch) Gap, Part 2,' attributing the September 3-4 spoofed-website campaign to a third actor, UTA0565, and naming the previously undocumented CLEANGULP malware family.
- CyberScoop and other outlets report on Volexity's UTA0565/CLEANGULP findings.
Sources cited for UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046
- Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
- Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
- Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
- Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
- CISA KEV Catalog Entry: CVE-2026-85046 (Google Chromium V8 Type Confusion Vulnerability)
- CISA KEV Catalog Entry: CVE-2026-87491 (Google Chromium V8 Out of Bounds Write Vulnerability)
- CISA KEV Catalog Entry: CVE-2026-85880 (Microsoft Windows Heap-Based Buffer Overflow Vulnerability)
- Stable Channel Update for Desktop (Chrome 153.0.8010.36/.37, fixes CVE-2026-87491)
- MSRC Vulnerability Guide: CVE-2026-85880 (Windows ALPC Elevation of Privilege)
- Google warns of new Chrome zero-day flaw exploited in attacks
- Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
More in zero day
- Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible Zero-Day Attack
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day Targeting
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense Industry
- European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit Chain)
Detection coverage for TL-2026-2681
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2681 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.