SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

UTA0565

❔ UnknownLast active: 2026-09-23First seen: 2026-09-23
3
linked CVEs
Targeted industries
GovernmentNGOMedia
In early September 2026, Chinese threat actor UTA0565 exploited unpatched zero-day vulnerabilities in Google Chrome and Microsoft Windows through sophisticated phishing campaigns. The actor registered fake domains impersonating legitimate organizations including China Digital Times and the Center for American Progress, sending targeted phishing emails to Asian government entities. Victims were directed to spoofed websites hosting an exploit chain leveraging CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The attacks delivered CLEANGULP, a previously undocumented malware family with backdoor capabilities including command execution, file operations, and beacon object file execution. The malware communicated with command-and-control infrastructure via encrypted HTTP traffic using custom encoding. Multiple Chinese APT groups demonstrated coordinated access to this exploit kit, suggesting widespread sharing within the Chinese cyber espionage community during the vulnerability window.
Source: otx · Collected: 2026-09-25
⚡ Vulnerabilities & Exploits3 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2026-85046
suspected

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS 8.8
KEV
CVE-2026-87491
suspected

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVSS 8.8
KEV
CVE-2026-85880
suspected

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVSS 7.8
KEV
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs14
domainthecovnresation.net—2026-09-23
sha1668aa5551315ab26b67118fbb29f8e4560a1e1af—2026-09-23
md5177652713dad3c128bd9195abf2b7603—2026-09-23
domainthecovnresation.com—2026-09-23
domainpersonclouds.com—2026-09-23
domainhalal-navi.net—2026-09-23
sha2568858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cb—2026-09-23
sha256cbeeb7dd5e89261cde032825fd10bb80bad2e3fbf5b91fdc9137ad463ffa8f21—2026-09-23
domainamericanprgoress.top—2026-09-23
domainchinadigitaltimes.top—2026-09-23
ip96.9.125.52—2026-09-23
domainoutsourcingwise.net—2026-09-23
urlhttps://americanprgoress.top/chrome_cleanup.exe—2026-09-23
domainhalaltak.net—2026-09-23
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.