Third Chinese APT Group Chains Chrome and Windows Zero-Day Exploits in Phishing Campaign Targeting Government Entities
Reuse of a single exploit chain across three distinct Chinese APT clusters, now corroborated by Proofpoint's separate sightings, points to a shared development-and-distribution pipeline inside China's cyber-espionage ecosystem rather than isolated tool theft. Reporting rests entirely on Volexity's own technical disclosure, amplified without independent verification by GBHackers, Cyber Security News, and The Hacker News. A shared exploit broker leasing the kit to multiple independent operators could produce the same pattern without central Ministry of State Security tasking. Patching the Chrome and Windows CVEs closes only those vulnerabilities: the kit's stable core and swappable payload architecture let operators re-arm quickly with new lures and backdoors. Additional registration-linked domains suggest disclosed campaigns are a fraction of total targeting, leaving government networks and Hong Kong/China human-rights advocacy groups exposed to follow-on variants after this patch cycle.
4 sources
- Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits -
Volexity - Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware -
The Hacker News - Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits -
Cyber Security News - Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits -
GBHackers