A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a previously undocumented backdoor.
The activity occurred on September 3 and 4, 2026, while the targeted vulnerabilities remained unpatched in Google Chrome.
It followed Volexity’s September 9 disclosure that UTA0560 and JungleBamboo, also known as APT31 or Violet Typhoon, had used the exploit chain in separate operations.
The growing number of operators using substantially similar code points to rapid sharing or distribution of a high-end browser exploitation capability within the broader Chinese cyber-espionage ecosystem.
UTA0565 used Chinese-language phishing emails aimed at Asian government entities, including a lure urging recipients to support imprisoned Hong Kong activist Chow Hang-tung and speak out against suppression of June 4 commemorations.
In another operation, the actor impersonated the Center for American Progress.
The emails directed targets to attacker-controlled domains made to resemble legitimate organizations.
Observed examples included chinadigitaltimes[.]top, impersonating China Digital Times, and americanprgoress[.]top, a typosquat of americanprogress[.]org.
Volexity found that the China Digital Times lure had been hosted on 96.9.125[.]52 and closely replicated the authentic site’s appearance.
The Center for American Progress clone remained active during analysis and pulled much of its visible content from the legitimate website, helping it evade immediate suspicion.
However, the threat actor inserted a concealed iframe pointing to /config.html. That hidden component triggered the browser exploit chain without changing what the victim saw in the visible page.
The operation chained three vulnerabilities: Chrome V8 type-confusion vulnerability CVE-2026-85046, Chrome V8 sandbox escape CVE-2026-87491, and Windows kernel local privilege escalation CVE-2026-85880.
Together, the vulnerabilities enabled code execution in Chrome, escape from the V8 sandbox, elevation of privileges on affected Windows systems, and injection into the parent Chrome process.

CVE-2026-85046 was a “patch-gap” vulnerability: the fix had entered Chromium’s public source code but was not yet available in released Chrome builds.
That disclosure-to-release interval gave operators an opportunity to reverse engineer the upstream fix and weaponize the vulnerability against users still running vulnerable stable versions.
Volexity tracks the cluster as UTA0565, which used the same exploit framework previously associated with other China-linked espionage activity but adapted it with convincing typosquatted websites and a new payload called CLEANGULP.
APT Exploits Chrome and Windows
Proofpoint has named the shared framework BlueMoon and reported at least four espionage-focused users of the kit, most with a suspected China nexus.
UTA0565’s implementation largely retained the same embedded p1, p2, and pp components previously documented by Volexity. The key operational change was the final stage.
Rather than invoking cmd.exe and curl.exe to retrieve a payload, the modified loader downloaded chrome_cleanup.exe, removed its Mark of the Web, and launched it through the Windows shell using COM.
The final payload, chrome_cleanup.exe, is a 893 KB 64-bit executable with SHA-256 hash 8858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cb.
Volexity identified it as CLEANGULP, a previously undocumented malware family written in C, compiled with Microsoft Visual C++, and heavily obfuscated through control-flow flattening and indirect calls.
CLEANGULP installs itself as %LOCALAPPDATA%MicrosoftIMEMicrosoftIME.exe and creates a scheduled task named MicrosoftIME for persistence.
Its command set supports shell execution, process enumeration, file upload and download, and beacon object file execution giving operators a flexible post-compromise platform for reconnaissance and follow-on operations.
The malware communicates with thecovnresation[.]com, a typosquat of media network The Conversation.
It uses HTTP for command-and-control traffic, encrypting request and response bodies with AES-256-GCM before Base64 encoding them with a custom alphabet.
Its first beacon registers a time-derived identifier that resembles a UUID but does not conform to RFC 9562.
Volexity linked several newly registered lookalike domains to UTA0565 with medium confidence, including outsourcingwise[.]net, halal-navi[.]net, halaltak[.]net, borneobulletins[.]top, and both thecovnresation[.]net and thecovnresation[.]com.
These domains impersonate media outlets, corporate-training services, restaurant directories, and other legitimate entities, and likely served as exploit hosts, malware-delivery points, or C2 infrastructure.
The case highlights an increasingly dangerous model: multiple operators can reuse a shared exploit core while independently replacing lures, infrastructure, loaders, and malware.
Security teams should urgently apply Chrome and Windows security updates, block the identified typosquatted domains, investigate suspicious Chrome child-process activity, and hunt for MicrosoftIME.exe under user-local application data and scheduled tasks named MicrosoftIME.
Proofpoint also warned that BlueMoon’s rapid adoption suggests the capability could spread to additional espionage and financially motivated actors.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

