hacker-news · Crawled Sep 23, 2026
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
5 IoCs 1 CVEs
Read original article ↗
AI Summary
A Chinese threat actor, UTA0565, exploited a zero-day chain involving vulnerabilities in Google Chrome and Microsoft Windows to deploy a new malware family named CLEANGULP. The attacks, observed on September 3 and 4, 2026, used fake websites mimicking media organizations and NGOs to deliver the BlueMoon exploit kit, which leveraged CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escape the browser sandbox and execute code remotely. The malware, delivered as 'chrome_cleanup.exe', communicates with a hard-coded C2 domain and provides capabilities including command execution, process listing, file upload/download, and beacon object file execution.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 5 extracted
MITRE ATT&CK TTPs 21 techniques
T1005 Data from Local System · Collection T1021 Remote Services · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1048 Exfiltration Over Alternative Protocol · Exfiltration T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1055.012 Process Hollowing · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1082 System Information Discovery · Discovery T1085 T1085 T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1189 Drive-by Compromise · Initial Access T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1566 Phishing · Initial Access