As cited
Copy frozen at (site build).
vulnerabilities
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
A Chinese advanced persistent threat (APT) group tracked as UTA0565 deployed chained zero-day vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) through spoofed websites impersonating legitimate media organizations and nonprofits. The actor sent phishing emails to Asian government entities and other targets, directing them to fake sites that delivered a previously undocumented malware family called CLEANGULP with capabilities including command execution, file transfer, and persistence through scheduled tasks. This represents a third distinct Chinese APT leveraging the same exploit chain, suggesting the toolkit has been shared across multiple threat actors within the Chinese cyberattack community.
Why it matters: Organizations globally should assume they may be targeted by this campaign if they received phishing emails from September 3-4, 2026; practitioners need to patch Chrome and Windows immediately, monitor for CLEANGULP indicators, and block the identified typosquat domains (thecovnresation[.]com, americanprgoress[.]top, and others) across their networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
A Chinese advanced persistent threat (APT) group tracked as UTA0565 deployed chained zero-day vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) through spoofed websites impersonating legitimate media organizations and nonprofits. The actor sent phishing emails to Asian government entities and other targets, directing them to fake sites that delivered a previously undocumented malware family called CLEANGULP with capabilities including command execution, file transfer, and persistence through scheduled tasks. This represents a third distinct Chinese APT leveraging the same exploit chain, suggesting the toolkit has been shared across multiple threat actors within the Chinese cyberattack community.
Why it matters: Organizations globally should assume they may be targeted by this campaign if they received phishing emails from September 3-4, 2026; practitioners need to patch Chrome and Windows immediately, monitor for CLEANGULP indicators, and block the identified typosquat domains (thecovnresation[.]com, americanprgoress[.]top, and others) across their networks.
- Source published
- First seen by Cybersecurity Tracker