Adversary Intelligence — 2026-09-25

Third Chinese APT Group Chains Chrome and Windows Zero-Day Exploits in Phishing Campaign Targeting Government Entities

BLUFConfirmed sharing of a zero-day exploit kit across three Chinese APT clusters reveals an industrialized supply chain that will outlast any single patch cycle.

Volexity reported that a third China-linked threat actor, tracked as UTA0565, chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) on September 3 and 4, before the flaws were patched 1. The group used spoofed websites impersonating China Digital Times and the Center for American Progress, sending phishing emails to Asian government entities and a lure referencing jailed Hong Kong activist Chow Hang-tung 1. A hidden iframe on the fake Center for American Progress site delivered a previously undocumented backdoor Volexity calls CLEANGULP, which is obfuscated using control flow flattening, installs as a scheduled task, and communicates over HTTP with hardcoded command-and-control domain thecovnresation[.]com 1. Volexity assessed the exploit kit shares core code with two other Chinese APT actors it disclosed on September 9, and noted Proofpoint identified separate users of the same kit 1. The Hacker News and Cyber Security News corroborated the CVE chain, target set, and CLEANGULP delivery mechanism in their reporting 23.

Analysis
Reuse of a single exploit chain across three distinct Chinese APT clusters, now corroborated by Proofpoint's separate sightings, points to a shared development-and-distribution pipeline inside China's cyber-espionage ecosystem rather than isolated tool theft. Reporting rests entirely on Volexity's own technical disclosure, amplified without independent verification by GBHackers, Cyber Security News, and The Hacker News. A shared exploit broker leasing the kit to multiple independent operators could produce the same pattern without central Ministry of State Security tasking. Patching the Chrome and Windows CVEs closes only those vulnerabilities: the kit's stable core and swappable payload architecture let operators re-arm quickly with new lures and backdoors. Additional registration-linked domains suggest disclosed campaigns are a fraction of total targeting, leaving government networks and Hong Kong/China human-rights advocacy groups exposed to follow-on variants after this patch cycle.
4 sources
  1. Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits - Volexity
  2. Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware - The Hacker News
  3. Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits - Cyber Security News
  4. Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits - GBHackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE