Volexity analysts Damien Cash and Tom Lancaster reported that the group chained two Chrome flaws (CVE‑2026‑85046 and CVE‑2026‑87491) with a Windows Advanced Local Procedure Call bug (CVE‑2026‑85880) to break out of the browser sandbox and achieve remote code execution on victim machines.
Unlike earlier campaigns that relied on a single malicious site, UTA0565 deployed a network of fake webpages that pretended to be reputable media outlets and a non‑governmental organization, using hidden iframes to load a malicious HTML element called "config.html".
The element delivered the BlueMoon exploit kit, which combined the three zero‑days and dropped a shellcode payload named "pp" that fetched an executable dubbed "chrome_cleanup.exe" from a bogus domain.
The final payload, a malware family dubbed CLEANGULP, is compiled with Microsoft Visual C and offers a range of capabilities, including command‑shell access, process listing, file upload and download, and execution of beacon object files (BOF).
One observed campaign targeted Asian government entities with bilingual phishing emails that invoked support for Hong Kong activist Chow Hang‑tung and masqueraded as the Center for American Progress. The emails contained spoofed links to "chinadigitaltimes.top" and "americanprgoress.top", which mimicked legitimate sites before triggering the exploit chain.
CLEANGULP contacts its command‑and‑control server via HTTP on a hard‑coded domain, thecovnresation.com, deliberately resembling the nonprofit news outlet The Conversation, a tactic that may aid evasion and credibility.
Volexity cautioned that the exploit kit appears to be shared across multiple actors in the Chinese cyber‑espionage community, suggesting a coordinated effort to weaponise the same core code. The two organizations that reported the activity acknowledge that the true scale and impact could be far wider.