Volexity has identified a second China-aligned threat group, tracked as UTA0565, exploiting the same Chrome and Windows zero-day chain that CyberTech previously reported another Chinese actor using against Chrome and Windows targets. The new campaign, spotted September 3 and 4, chained a Chrome V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel local privilege-escalation flaw (CVE-2026-85880) to reach SYSTEM privileges, deploying a previously undocumented backdoor Volexity calls CLEANGULP.

UTA0565 tailored its lures to distinct audiences. One phishing wave, aimed at Asian government entities, urged recipients to publicly support imprisoned Hong Kong activist Chow Hang-tung and speak out against the suppression of June Fourth commemorations. A separate campaign spoofed the Center for American Progress through a typosquatted domain. Both led to fake websites built to silently trigger the exploit chain in a visitor’s browser. CLEANGULP installs itself disguised as a Microsoft IME component, persists through a scheduled task, and communicates over AES-256-GCM encrypted channels supporting shell access, process listing, and file upload and download.

Two independently tracked Chinese-aligned actors reusing the same exploit chain within roughly two weeks of each other, against unrelated target sets, points to shared tooling or exploit access between operationally separate operators rather than a single group’s campaign. Since the underlying patches were already public when both waves hit, the operative defense is not zero-day prevention but patch latency: any gap between a browser or OS patch shipping and full deployment that stretches past days, not weeks, is now inside the window multiple unrelated actors will independently find and use, a dynamic CyberTech has also seen play out in North Korea’s reuse of the same typosquat-driven delivery pattern across unrelated campaigns.

Source: Volexity