Opens in a new tab

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

  • Home
  • Blog
  • Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Browser attacks Windows system to deliver CLEANGULP malware via shattered exploit chain

Defenders gained fresh insight into a Chinese-linked espionage campaign that weaponized a previously undisclosed Google Chrome and Microsoft Windows exploit chain to install a new backdoor called CLEANGULP on targeted systems. The attacks, detected on September 3 and 4, 2026, used spoofed versions of real news and policy websites to lure victims, then chained two Chrome flaws with a Windows privilege-escalation bug to escape the browser sandbox and run code directly on the host.

What the attack chain looks like

The operation relied on three vulnerabilities working together:

  • CVE-2026-85046, a Google Chrome flaw used in the initial browser compromise.
  • CVE-2026-87491, a second Chrome vulnerability chained to deepen control inside the browser.
  • CVE-2026-85880, a bug in the Windows Advanced Local Procedure Call (ALPC) component used to break out of the Chrome sandbox and gain full code execution on the machine.

Once the chain succeeded, a final shellcode stage pulled a loader named chrome_cleanup.exe from the attacker’s infrastructure. That loader then deployed CLEANGULP, the actual malware payload.

How the lures were built

The threat actor, tracked as UTA0565, posed as media outlets and a non-governmental organization to reach its targets. One campaign aimed at Asian government entities used phishing emails written in both Chinese and English, urging recipients to support a Hong Kong activist. The messages impersonated the Center for American Progress and pointed victims to look-alike domains such as chinadigitaltimes[.]top and americanprgoress[.]top, replicas of China Digital Times and the real CAP site.

Those spoofed pages loaded a hidden iframe that silently delivered a shared exploit kit researchers call BlueMoon, the same kit observed in earlier Chinese campaigns. The BlueMoon kit combined all three CVEs and staged the chrome_cleanup.exe download.

Researchers noted that unlike previously documented Chinese exploitation activity, UTA0565 stood out for using multiple fake websites rather than a single landing page, giving the campaign more resilience and a wider net.

Inside the CLEANGULP backdoor

CLEANGULP is compiled with the Microsoft Visual C++ toolchain and operates as a hands-on remote access tool. It supports five core commands for the operator:

  • shell: run an arbitrary command on the compromised host.
  • ps: list currently running processes.
  • upload: send a file from the operator to the victim.
  • download: exfiltrate a file from the victim to the operator.
  • bof: execute a Beacon Object File (BOF), a small, in-memory post-exploitation module.

Command and control traffic flows over HTTP to a hard-coded domain, thecovnresation[.]com, chosen to mimic the legitimate nonprofit news site theconversation[.]com. This typo-squatting is a common tactic to slip past casual network inspections.

What the BlueMoon kit tells defenders

Researchers tied CLEANGULP and its delivery chain back to the BlueMoon exploit kit, which has surfaced across at least four separate Chinese state-aligned groups. The kit is modular: the core browser-escape and Windows ALPC stages appear to be shared, while each group customizes the lure, the loader, and the final payload. That pattern points to a coordinated ecosystem within the Chinese cyber-espionage community, where tooling is developed centrally and handed to multiple operators.

Because Volexity and another organization are the only two to have publicly reported on this wave of exploitation, the true scope is almost certainly wider than what is visible today. Organizations that match the targeting profile, particularly government agencies, policy think tanks, and NGOs focused on Asia, should treat the three CVEs as a priority for patching and detection.

What to patch and what to watch

The exposure here is straightforward: any system running an unpatched Chrome browser on a Windows host is in scope, because the chain runs entirely through normal web browsing. Patching Chrome to a build that includes fixes for CVE-2026-85046 and CVE-2026-87491 removes the browser-side entry point, and patching Windows for CVE-2026-85880 removes the sandbox escape that turns browser access into full code execution.

For detection, defenders should hunt for the chrome_cleanup.exe filename appearing in process trees launched by a browser, and for outbound HTTP traffic to look-alike domains built around common news outlets, advocacy organizations, or policy think tanks. The BlueMoon chain’s staged nature also leaves fingerprints: a hidden iframe loading an HTML configuration file from an unrelated domain is a strong signal of this kit, even when the final payload changes.

FAQ

What is the CLEANGULP malware?

CLEANGULP is a Windows backdoor deployed through a Chrome and Windows exploit chain. It gives operators five capabilities: running shell commands, listing processes, uploading files, downloading files, and executing Beacon Object Files for in-memory post-exploitation.

Which vulnerabilities did the Chrome-Windows zero-day chain use?

The chain combined two Google Chrome flaws, CVE-2026-85046 and CVE-2026-87491, with a Windows Advanced Local Procedure Call bug, CVE-2026-85880, to break out of the browser sandbox and run code on the host.

Who was targeted by the UTA0565 campaign?

Asian government entities were the primary target. Victims were lured through phishing emails written in Chinese and English that spoofed the Center for American Progress and used fake replicas of news and policy sites to deliver the BlueMoon exploit kit.


This article summarizes reporting from thehackernews.com.

← All Articles