Full Report
The threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups. The post Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects appeared first on CyberScoop.
Analysis Summary
# Threat Actor: UTA0565
## Attribution & Identity
* **Identification:** A state-aligned Chinese espionage threat group.
* **Aliases/Associated Groups:**
* Tracked by Volexity as **UTA0565**.
* Associated with a broader "Chinese computer network exploitation community" that shares resources.
* Linked via shared exploit kits to groups identified by Proofpoint as **APT31**, **UNK_LateNight**, **UNK_DoubleCheck**, and **UNK_QuietRacket**.
## Activity Summary
In early September 2026, UTA0565 conducted highly targeted cyber-espionage campaigns utilizing a "triple-link chain" of zero-day vulnerabilities. The actor stood out by using sophisticated social engineering, including fake websites and politically themed phishing lures, to deliver a previously undocumented malware payload. The activity occurred just days before the vulnerabilities were publicly disclosed or patched by Microsoft and Google.
## Tactics, Techniques & Procedures
* **Zero-Day Exploitation:** Chaining multiple vulnerabilities to achieve remote code execution and privilege escalation.
* **Social Engineering:**
* **Phishing:** Sending emails with political themes (e.g., support for Hong Kong activist Chow Hang-tung).
* **Typosquatting/Impersonation:** Creating fake domains to impersonate legitimate organizations.
* **Decoy Content:** Using real content from legitimate websites to reduce user suspicion and mask malicious activity.
* **Vulnerability Chain:**
* **CVE-2026-85046 & CVE-2026-87491:** Remote Code Execution (RCE) in the Chromium JavaScript engine.
* **CVE-2026-85880:** Privilege escalation in Windows Advanced Local Procedure Call (ALPC).
## Targeting
* **Sectors:** Government entities, media organizations, corporate training organizations, and non-profits/think tanks.
* **Geography:** Specifically noted targeting of **Asian** government entities.
* **Victims:**
* Asian government officials.
* Users interested in the Center for American Progress and China Digital Times.
* Visitors of halal restaurant search websites.
## Tools & Infrastructure
* **Malware:** **CLEANGULP** (a previously undocumented malware family).
* **Exploit Kit:** A shared Chinese-origin exploit kit weaponized for Chromium and Windows.
* **Infrastructure:**
* **Spoofed Domains:** Impersonating `americanprogress[.]org` and `chinadigitaltimes[.]net` (examples based on actor behavior).
* **Fake Websites:** Used to host exploit code and decoy material.
## Implications
The activity indicates a high level of coordination and resource sharing among Chinese state-sponsored actors. The "patch gap" exploitation—striking just before disclosure—suggests advanced reconnaissance of vendor patch cycles. UTA0565’s specific focus on polished social engineering and the use of the CLEANGULP payload represents a technical and operational evolution compared to peer groups, making them a high-tier threat to government and civil society targets.
## Mitigations
* **Browser Patching:** Ensure all Chromium-based browsers (Chrome, Edge, etc.) are updated immediately to address CVE-2026-85046 and CVE-2026-87491.
* **OS Updates:** Apply Microsoft September 2026 security updates to patch the ALPC privilege escalation (CVE-2026-85880).
* **Email Security:** Implement advanced phishing protection to detect spoofed domains and impersonation attempts.
* **Endpoint Monitoring:** Monitor for suspicious ALPC activity and unusual browser-spawned processes indicative of the CLEANGULP payload.