Volexity researchers have identified a Chinese state-aligned threat group, known as UTA0565, taking advantage of a chain of zero-day vulnerabilities in both Chrome and Microsoft products. These vulnerabilities were exploited between September 3 and 4, prior to their disclosure or any available patches. The group's activities coincide with other spikes noted by threat hunters and are linked to multiple Chinese espionage groups. However, UTA0565 distinguished itself by using numerous fake websites to deceive victims. Notably, they targeted Asian government entities with phishing emails urging support for Hong Kong activist Chow Hang-tung. They also impersonated domains like the Center for American Progress and China Digital Times in other phishing attempts.
Volexity observed that UTA0565 used a consistent exploit kit shared across various Chinese threat groups, indicating a coordinated effort within this community. The vulnerabilities involved are CVE-2026-85046 and CVE-2026-87491, which are remote code execution defects in Chromium-based browsers, and CVE-2026-85880, a privilege escalation zero-day in Windows Advanced Local Procedure Call disclosed on September 8. Proofpoint, another cybersecurity firm, had previously noted these vulnerabilities being used by multiple state-aligned groups since last August, including APT31 and others.
UTA0565 has employed a novel malware family named 'CLEANGULP' and has targeted a range of entities such as media organizations, halal restaurant search websites, and corporate training bodies. Volexity remarked on the group's technical and operational advancements in their campaigns, particularly in how they utilized real content from legitimate websites to lower user suspicion.

