Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects

Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Volexity found the Chinese threat group UTA0565 exploiting a chain of zero-day vulnerabilities in Chrome and Microsoft products across multiple phishing campaigns. The group used fake websites, spoofed domains, and a previously undocumented malware family called CLEANGULP to target Asian government entities and other organizations. #UTA0565 #CVE-2026-85046 #CVE-2026-87491 #CVE-2026-85880 #CLEANGULP #Chow_Hang-tung

Keypoints

  • UTA0565 exploited a triple-link chain of zero-day vulnerabilities before patches were available.
  • The attacks targeted Chrome-based browsers and Microsoft Windows systems.
  • Phishing emails used fake websites and spoofed domains to deceive victims.
  • UTA0565 deployed the previously undocumented malware family CLEANGULP.
  • Researchers linked similar exploit-kit components to multiple Chinese threat groups.

Read More: https://cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/