UTA0565
❔ UnknownLast active: 2026-09-23First seen: 2026-09-23
3
linked CVEs
Targeted industries
GovernmentNGOMedia
In early September 2026, Chinese threat actor UTA0565 exploited unpatched zero-day vulnerabilities in Google Chrome and Microsoft Windows through sophisticated phishing campaigns. The actor registered fake domains impersonating legitimate organizations including China Digital Times and the Center for American Progress, sending targeted phishing emails to Asian government entities. Victims were directed to spoofed websites hosting an exploit chain leveraging CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The attacks delivered CLEANGULP, a previously undocumented malware family with backdoor capabilities including command execution, file operations, and beacon object file execution. The malware communicated with command-and-control infrastructure via encrypted HTTP traffic using custom encoding. Multiple Chinese APT groups demonstrated coordinated access to this exploit kit, suggesting widespread sharing within the Chinese cyber espionage community during the vulnerability window.
Source: otx · Collected: 2026-09-25
⚡ Vulnerabilities & Exploits3 CVEs
threat_actor_cve → cves / exploits.cve_ids
| CVE-2026-85046 suspected | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | CVSS 8.8 KEV |
| CVE-2026-87491 suspected | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | CVSS 8.8 KEV |
| CVE-2026-85880 suspected | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. | CVSS 7.8 KEV |
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs14
| domain | thecovnresation.net | — | 2026-09-23 |
| sha1 | 668aa5551315ab26b67118fbb29f8e4560a1e1af | — | 2026-09-23 |
| md5 | 177652713dad3c128bd9195abf2b7603 | — | 2026-09-23 |
| domain | thecovnresation.com | — | 2026-09-23 |
| domain | personclouds.com | — | 2026-09-23 |
| domain | halal-navi.net | — | 2026-09-23 |
| sha256 | 8858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cb | — | 2026-09-23 |
| sha256 | cbeeb7dd5e89261cde032825fd10bb80bad2e3fbf5b91fdc9137ad463ffa8f21 | — | 2026-09-23 |
| domain | americanprgoress.top | — | 2026-09-23 |
| domain | chinadigitaltimes.top | — | 2026-09-23 |
| ip | 96.9.125.52 | — | 2026-09-23 |
| domain | outsourcingwise.net | — | 2026-09-23 |
| url | https://americanprgoress.top/chrome_cleanup.exe | — | 2026-09-23 |
| domain | halaltak.net | — | 2026-09-23 |
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.