UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP Malware

UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046 (TL-2026-2681) is a critical-severity zero-day vulnerability scored CVSS 8.8, first published 2026-09-27. It is attributed to UTA0565 (China) with high confidence, affects Google Chrome, references 3 CVEs (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880), maps to 14 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2681

Threat ID
TL-2026-2681
Severity
CRITICAL
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
ZERO_DAY
First published
2026-09-27
Last reviewed
2026-09-27
Attribution
UTA0565
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, news - media, ngo
Target regions
Asia, North America
Detection rules
9
Indicators of compromise
17

Malware and tooling in UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046

Malware and tooling: CLEANGULP

Volexity reports that China-aligned threat group UTA0565 chained two Chrome zero-days with a Windows ALPC privilege-escalation zero-day to compromise targets between September 3-4, 2026, before any of the three CVEs were patched or disclosed, deploying a previously undocumented malware family, CLEANGULP, via phishing emails and spoofed media/NGO websites.

How UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046 works

Between September 3 and 4, 2026, the China-aligned threat group UTA0565 chained two unpatched Google Chrome zero-days (CVE-2026-85046, a V8 type-confusion bug providing arbitrary read/write inside the browser sandbox, and CVE-2026-87491, a V8 out-of-bounds write enabling sandbox escape) with a Windows Advanced Local Procedure Call kernel privilege-escalation zero-day (CVE-2026-85880, rooted in the RtlpCreateServerAcl code path) to fully compromise victim hosts before any of the three vulnerabilities were publicly disclosed or patched.

UTA0565 delivered the chain via phishing emails that linked to a network of spoofed websites impersonating legitimate media and policy organizations, including chinadigitaltimes[.]top (spoofing chinadigitaltimes.net) and americanprgoress[.]top (a typosquat of americanprogress.org), registered between September 2 and 4, 2026 and hosted behind 96.9.125[.]52. Victims who visited a fake site triggered a hidden iframe (config.html) that ran the same web-worker-based, three-stage position-independent exploit chain (host reconnaissance, kernel-mode privilege escalation, browser-process injection) that Volexity had already documented on September 9, 2026 as shared by two other Chinese threat actors, UTA0560 and JungleBamboo (APT31/Violet Typhoon/TA412), against the identical three CVEs. Volexity assesses that the byte-identical shellcode across unrelated operators points to a common exploit developer supplying multiple China-nexus groups during the Chrome/Windows patch gap.

Following successful exploitation, UTA0565 dropped a previously undocumented malware family, CLEANGULP, delivered as chrome_cleanup.exe and installed to %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe, persisting via a scheduled task named "MicrosoftIME." CLEANGULP is a control-flow-flattened, indirect-call-obfuscated backdoor supporting shell command execution, process listing, file upload/download, and Beacon Object File (BOF) execution. It communicates over HTTP POST to /beacon/pre-register on the typosquatted C2 domain thecovnresation[.]com (spoofing theconversation.com), encrypting traffic with AES-256-GCM using a key derived from the SHA-256 hash of a custom Base64 alphabet embedded in the binary.

Google patched CVE-2026-85046 on September 4, 2026 (Chrome 152.0.7977.82/.83) and CVE-2026-87491 on September 8, 2026 (Chrome 153.0.8010.36/.37); Microsoft patched CVE-2026-85880 on September 8, 2026 as part of its September Patch Tuesday. CISA added all three CVEs to its Known Exploited Vulnerabilities catalog. Volexity published its UTA0565-specific findings, including the CLEANGULP attribution, on September 21, 2026.

MITRE ATT&CK techniques used in TL-2026-2681

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Persistence

T1053 Scheduled Task/Job

Privilege Escalation

T1055 Process Injection

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Command and Control

T1071 Application Layer Protocol; T1573 Encrypted Channel

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure

Affected products and versions in UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046

  • Google — Chrome
    Vulnerable versions: < 152.0.7977.82 (CVE-2026-85046)
    Fixed in: 152.0.7977.82; 152.0.7977.83
  • Google — Chrome
    Vulnerable versions: < 153.0.8010.36 (CVE-2026-87491)
    Fixed in: 153.0.8010.36; 153.0.8010.37
  • Microsoft — Windows
    Vulnerable versions: Windows 10 1607; Windows 10 1809; Windows 10 21H2; Windows 10 22H2; Windows Server 2012; Windows Server 2012 R2; Windows Server 2016; Windows Server 2019; Windows Server 2022
    Fixed in: September 2026 cumulative update (CVE-2026-85880)

Remediation for UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046

Patches

  • Google Chrome 152.0.7977.82/.83 (fixes CVE-2026-85046)
  • Google Chrome 153.0.8010.36/.37 (fixes CVE-2026-87491)
  • Microsoft September 2026 Patch Tuesday cumulative update (fixes CVE-2026-85880)

Immediate actions

  • Patch Chrome to >=153.0.8010.36/.37 and apply the September 2026 Windows cumulative update to all endpoints immediately
  • Block/sinkhole the identified UTA0565 domains (chinadigitaltimes.top, americanprgoress.top, thecovnresation.com, thecovnresation.net, personclouds.com, halal-navi.net, borneobulletins.top) and 96.9.125.52 at the perimeter and DNS resolver
  • Hunt for the 'MicrosoftIME' scheduled task and %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe on Windows endpoints
  • Hunt for outbound HTTP POST traffic to /beacon/pre-register, especially against typosquatted news/media domains

Workarounds

  • Restrict or closely monitor execution from %LOCALAPPDATA%\Microsoft\IME\ pending patch deployment
  • Apply CISA BOD 26-04 mitigations per the KEV catalog entries for all three CVEs

Longer-term hardening

  • Deploy EDR with behavioral detection for BOF/shellcode execution and process injection into browser processes
  • Stand up typosquat/DNS-lookalike monitoring for organizations frequently impersonated in these campaigns (media outlets, policy NGOs, government agencies)
  • Reduce patch-gap exposure by tracking upstream Chromium security fixes and staged rollouts ahead of general stable-channel availability

CVEs associated with UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046

CVE-2026-85046, CVE-2026-87491, CVE-2026-85880

Weaknesses (CWE) in UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046

CWE-843, CWE-787, CWE-122, CWE-908

Timeline of UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046

  • CVE-2026-85046 (V8 type confusion) is privately reported to the Chromium project, entering the Chromium public source tree ahead of a stable Chrome release and opening the 'patch gap' window the exploit chain would abuse.
  • Independent researcher Jihyeon Jeong reports the V8 out-of-bounds write later designated CVE-2026-87491 to Google, earning a $2,500 bug bounty; this bug forms the sandbox-escape stage of the same exploit chain.
  • UTA0565 begins registering the spoofed lure domains used in the campaign, including chinadigitaltimes.top, americanprgoress.top, thecovnresation.com/.net, personclouds.com, halal-navi.net, and borneobulletins.top.
  • Volexity observes UTA0565 exploiting the still-unpatched Chrome and Windows zero-day chain via spoofed media/NGO websites to deploy the CLEANGULP backdoor against targets.
  • Google ships Chrome 152.0.7977.82/.83, fixing CVE-2026-85046; CISA adds the CVE to its Known Exploited Vulnerabilities catalog the same day with an September 18 remediation deadline.
  • Google ships Chrome 153.0.8010.36/.37, fixing CVE-2026-87491.
  • Microsoft's September 2026 Patch Tuesday fixes CVE-2026-85880 (Windows ALPC heap-based buffer overflow); CISA adds it to KEV with a September 22 remediation deadline for federal agencies.
  • Volexity publishes 'Mind the (Patch) Gap,' documenting two other Chinese threat actors, UTA0560 and JungleBamboo (APT31/Violet Typhoon/TA412), independently abusing the identical three-CVE exploit chain; CISA adds CVE-2026-87491 to KEV.
  • Volexity publishes 'Mind the (Patch) Gap, Part 2,' attributing the September 3-4 spoofed-website campaign to a third actor, UTA0565, and naming the previously undocumented CLEANGULP malware family.
  • CyberScoop and other outlets report on Volexity's UTA0565/CLEANGULP findings.

Sources cited for UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046

More in zero day

Detection coverage for TL-2026-2681

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2681 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats