Volexity has released a follow-up on its report published earlier this month detailing attacks by two Chinese threat actors involving chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880).
In the new report the company said that a third Chinese threat actor, tracked as UTA0565, had used the same chain of Chrome and Windows zero-day exploits.
The attacks, observed on September 3–4 while the vulnerabilities were still unpatched, exploited Google Chrome vulnerabilities CVE-2026-85046 and CVE-2026-87491, followed by Windows local privilege escalation vulnerability CVE-2026-85880.
UTA0565 used spoofed websites rather than relying only on direct exploit links. One campaign targeted Asian government entities with Chinese-language phishing emails; another impersonated the Center for American Progress. The domain americanprgoress[.]top was a typosquat that loaded content from the legitimate website but embedded an iframe containing the exploit chain.
The exploit code was largely the same as in previously observed attacks, although UTA0565 used a different payload. Volexity identified the payload as a previously undocumented malware family named CLEANGULP.
CLEANGULP is written in C and compiled with Microsoft Visual C. The malware uses heavy control-flow obfuscation and indirect calls to make analysis more difficult. It communicates with a hardcoded command-and-control domain (thecovnresation[.]com), which impersonates the media organization The Conversation. Volexity observed HTTP traffic between the malware and its C&C server.
Researchers also found additional attacker-controlled domains impersonating media organizations, restaurant-search services, and corporate training companies. Volexity assessed with medium confidence that UTA0565 used the domains to distribute exploits or malware and, in some cases, for post-infection command and control.