MediumII Cyber Warfare & Critical Infrastructure22 September 2026, Tuesday
Volexity: China-linked UTA0565 used a 3-flaw Chrome–Windows chain via fake sites against Asian governments; groups using the same kit rise to 5
Volexity disclosed on 21 September that China-linked UTA0565 chained 2 Chrome flaws and 1 Windows flaw on 3–4 September to plant new malware called CLEANGULP in government bodies in Asia. Proofpoint had counted 4 groups using the same kit; UTA0565 is the fifth.
According to Volexity's report dated 21 September and a CyberScoop article dated 22 September, on 3 and 4 September 2026 UTA0565 chained the then-unpatched CVE-2026-85046 and CVE-2026-87491 (Chrome) with CVE-2026-85880 (Windows ALPC) to escape the browser sandbox and execute code on target systems. The Windows flaw was publicly disclosed on 8 September. The group used several fake websites impersonating legitimate organisations; in one campaign, phishing emails in Chinese and English were sent to government bodies in Asia, impersonating the US-based Center for American Progress and calling for support for Hong Kong activist Chow Hang-tung.
Volexity reported, by inference from the fake domain names, that there were victims in Brunei and Japan, and said it had identified 10 additional fake domains with medium confidence. According to The Hacker News, CLEANGULP is a heavily obfuscated implant written in C; it supports command execution, process listing, file transfer and BOF execution, and achieves persistence through a scheduled task disguised as Microsoft IME. According to CyberScoop, Proofpoint had identified at least 4 groups (APT31, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket) using the same exploit kit; Volexity assessed that the core kit is shared within China's computer network exploitation community and customised by multiple groups. The number of victims was not disclosed and could not be verified.
Talay assessment
Bottom line
The circulation of the same zero-day chain among at least 5 China-linked groups points to a production model in which exploit kits are shared centrally. This means targets will remain at risk well after patches are released; Asian governments and civil society critical of China are at the top of the target list.
Likely effects
- Asian public-sector securityNegativeWeeks
Targeting of governments such as Brunei and Japan through fake institutional websites raises the risk of leaks of diplomatic correspondence and policy documents in the region.
- Patch managementNegative1–6 months
Exploitation of 3 flaws before they were patched, and sharing of the kit among 5 groups, extends the attack window at organisations that are slow to apply Chrome and Windows updates.
- Turkish institutionsUncertainWeeks
The phishing impersonated a US-based organisation, so target selection is not bound by geography; rapid application of Chrome and Windows patches at Turkish public and defence bodies is the basic safeguard against the same risk.
Possibilities, ranked
- 1Kit spreads to new groups55%
In the coming weeks, other security firms report new China-linked clusters using the same chain.
Watch: New cluster reports with UNK_ or UTA designations from Proofpoint, Google TAG and Microsoft
- 2Impact fades with patching30%
As patches spread, campaigns move on to new flaws and this chain loses relevance.
Watch: Whether new Chrome/Windows flaws are added to CISA's KEV catalogue
- 3Diplomatic response15%
Japan or Brunei formally attributes the attacks to China and takes diplomatic action.
Watch: An official attribution statement from Japan's National Cybersecurity Office or foreign ministry
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Flaws chained▼ 3
- Chinese groups using the kit▼ at least 5
- Additional fake domains▼ 10