CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Permanent story citation

Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8088

As cited

Copy frozen at (site build).

vulnerabilities

Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits

A Chinese advanced persistent threat (APT) group tracked as UTA0565 deployed chained zero-day vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) through spoofed websites impersonating legitimate media organizations and nonprofits. The actor sent phishing emails to Asian government entities and other targets, directing them to fake sites that delivered a previously undocumented malware family called CLEANGULP with capabilities including command execution, file transfer, and persistence through scheduled tasks. This represents a third distinct Chinese APT leveraging the same exploit chain, suggesting the toolkit has been shared across multiple threat actors within the Chinese cyberattack community.

Why it matters: Organizations globally should assume they may be targeted by this campaign if they received phishing emails from September 3-4, 2026; practitioners need to patch Chrome and Windows immediately, monitor for CLEANGULP indicators, and block the identified typosquat domains (thecovnresation[.]com, americanprgoress[.]top, and others) across their networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits

A Chinese advanced persistent threat (APT) group tracked as UTA0565 deployed chained zero-day vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) through spoofed websites impersonating legitimate media organizations and nonprofits. The actor sent phishing emails to Asian government entities and other targets, directing them to fake sites that delivered a previously undocumented malware family called CLEANGULP with capabilities including command execution, file transfer, and persistence through scheduled tasks. This represents a third distinct Chinese APT leveraging the same exploit chain, suggesting the toolkit has been shared across multiple threat actors within the Chinese cyberattack community.

Why it matters: Organizations globally should assume they may be targeted by this campaign if they received phishing emails from September 3-4, 2026; practitioners need to patch Chrome and Windows immediately, monitor for CLEANGULP indicators, and block the identified typosquat domains (thecovnresation[.]com, americanprgoress[.]top, and others) across their networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary