hacker-news · Crawled Sep 23, 2026

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

5 IoCs 1 CVEs
Read original article ↗

AI Summary

A Chinese threat actor, UTA0565, exploited a zero-day chain involving vulnerabilities in Google Chrome and Microsoft Windows to deploy a new malware family named CLEANGULP. The attacks, observed on September 3 and 4, 2026, used fake websites mimicking media organizations and NGOs to deliver the BlueMoon exploit kit, which leveraged CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to escape the browser sandbox and execute code remotely. The malware, delivered as 'chrome_cleanup.exe', communicates with a hard-coded C2 domain and provides capabilities including command execution, process listing, file upload/download, and beacon object file execution.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 5 extracted

Type Value Detail
Domain chinadigitaltimes[.]top Details →
Domain americanprgoress[.]top Details →
Domain thecovnresation[.]com Details →
Filename config.html Details →
Filename chrome_cleanup.exe Details →

MITRE ATT&CK TTPs 21 techniques