Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Get our latest cybersecurity news first on Google.
Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday.
The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said.
The timing of the malicious activity mirrors other spikes threat hunters observed and attributed to multiple Chinese espionage threat groups. Yet, Volexity noted UTA0565’s campaigns differed from those attacks by using multiple fake websites to deceive victims.
Volexity shared phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung. The group spoofed domains impersonating the Center for American Progress and China Digital Times in other phishing emails.
While UTA0565 showcased a variance in tactics, it used the same components researchers observed in previous instances of the exploit kit across multiple Chinese threat groups.
“This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese computer network exploitation community, where the core kit was likely shared, customized, and weaponized by multiple groups,” Volexity wrote in the blog post. “The activity reported so far reflects only two organizations’ observations; the full scope and impact are likely far broader.”
The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Sept. 8 in Windows Advanced Local Procedure Call.
Proofpoint, which previously observed multiple state-aligned threat groups chaining the vulnerabilities together in attacks since last August, said a limited group of organizations were exposed to all three vulnerabilities in a short window.
Proofpoint previously attributed attacks involving the zero-days to APT31, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket. At the time it warned that attackers of other origins and motivations could strike soon as well.
Volexity said UTA0565 used a payload from a previously undocumented malware family it tracks as “CLEANGULP.” Researchers also found several domains likely used by UTA0565 in similar campaigns targeting media organizations, halal restaurant search websites and corporate training organizations.
“UTA0565’s use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns observed by Volexity, both in the mechanics of the exploitation and the presentation to end users,” researchers wrote. “Using real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.”
Latest Podcasts
Government
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
Dems seek top-to-bottom assessment of CISA workforce
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
The AI hacking apocalypse is not inevitable
Technology
Researchers use AI to find widespread software decoder flaw
What’s next for CISA's CDM program that gives cybersecurity tools to federal agencies
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
European parliament members call for slowdown of Serbia’s EU entry over spyware use
Threats
Early Scattered Spider member pleads guilty to cybercrime spree
Authorities seize popular, long-running DDoS-for-hire service domains
CISA promotes a fresh way to deter cyberattackers: Lie to them
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
Policy
Originally published by CyberScoop. © CyberScoop. Written by Matt Kapko.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-22 18:47 UTC
Related stories
- Apple patches CoreGraphics zero-day flaw exploited in attacks
BleepingComputer · 2026-09-29
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The Hacker News · 2026-09-29
- OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
The Hacker News · 2026-09-29
- One Packet Can Crash OT Servers in Industrial Sectors
Dark Reading · 2026-09-28