Cybercriminals are leveraging highly convincing replicas of legitimate websites to transform a routine web browsing session into a complete system compromise. By combining sophisticated phishing tactics with previously undisclosed vulnerabilities in Google Chrome and Microsoft Windows, attackers can quietly deploy malware on targeted devices with little indication that anything is wrong.
The campaign, observed on September 3 and 4 prior to public patches being released, relied on carefully crafted phishing emails that directed victims to attacker-controlled domains masquerading as reputable organizations. Rather than seeking widespread disruption, the operation appeared focused on espionage and intelligence gathering against selected targets, particularly government entities across Asia.
One lure used a Chinese-language message referencing imprisoned Hong Kong activist Chow Hang-tung, while another impersonated the Center for American Progress to increase credibility. Security researchers at Volexity attributed the activity to a China-linked threat actor tracked as UTA0565, describing the operation as a refined evolution of an exploit framework previously used by other groups.
According to Volexity, the attackers adopted an existing exploit toolkit but customized its delivery mechanisms, payloads, and supporting code to suit their objectives. These modifications suggest an effort to improve operational effectiveness while complicating detection and forensic analysis.
The campaign highlights the growing danger posed by modern phishing infrastructure. Unlike traditional scam websites that often contain obvious mistakes, these fraudulent pages closely mirror legitimate sites and may even load authentic content directly from the organizations they impersonate. As a result, even security-conscious users could struggle to identify warning signs.
Fake Websites Serve as the Initial Attack Vector
Each phishing email directed recipients to a malicious domain designed to closely resemble a trusted website. One fake page imitated China Digital Times, while another replicated much of the content found on the Center for American Progress website.
Behind the scenes, the attackers embedded a concealed iframe that loaded additional content in the background without altering the visible page. This hidden component executed a multi-stage exploit chain targeting both Chrome and Windows vulnerabilities.
The attack leveraged Chrome flaws CVE-2026-85046 and CVE-2026-87491, alongside the Windows privilege-escalation vulnerability CVE-2026-85880. Together, these vulnerabilities enabled attackers to escape Chrome's security sandbox and elevate privileges on the underlying Windows system.
In practical terms, the exploit chain allowed threat actors to move from a compromised browser session to deeper control over the operating system, creating a pathway for malware deployment and long-term persistence.
While UTA0565 retained much of the original exploit framework, researchers found several notable enhancements. The group introduced a new final-stage payload, modified supporting code, and altered various operational elements. The malware downloaded a replacement executable, removed Windows security warning markers attached to downloaded files, and launched the payload through native Windows shell components.
.webp)
Researchers also observed changes to variable names, debug messages, and logging functionality, indicating deliberate efforts to customize a shared toolkit and hinder security analysis.
CLEANGULP Malware Establishes Long-Term Access
The final payload delivered by the attack chain belongs to a newly identified malware family known as CLEANGULP. Designed with multiple anti-analysis techniques, the malware disguises itself as a legitimate Microsoft-related component before establishing persistence through scheduled tasks.
Once installed, CLEANGULP provides attackers with extensive remote access capabilities, including:
- Executing system commands
- Enumerating running processes
- Uploading and downloading files
- Deploying additional malicious payloads
- Executing operator-supplied code
The malware communicates with a hardcoded command-and-control server using standard HTTP traffic while encrypting its communications. This approach helps its network activity blend into normal web traffic, making detection significantly more difficult.
The operation also relied on typo-squatted domains that closely resembled legitimate organizations, reinforcing the illusion of authenticity during both the phishing phase and subsequent command-and-control communications.
Defensive Measures for Organizations
Security teams should prioritize the identification and investigation of potential indicators of compromise associated with this campaign. Recommended actions include:
- Reviewing DNS, proxy, and web traffic logs for connections to suspicious or lookalike domains.
- Investigating endpoints for signs of CLEANGULP infection and unauthorized scheduled tasks.
- Isolating affected systems immediately for forensic analysis.
- Deploying the latest Chrome and Windows security updates across all managed devices.
- Blocking known malicious infrastructure and domains associated with the campaign.
- Monitoring unmanaged and remote endpoints that may have missed critical browser updates.
- Configuring email gateways to detect and flag newly registered lookalike domains.
- Educating employees to independently verify unexpected advocacy, policy, or government-related emails before interacting with links or attachments.
The campaign serves as a reminder that a single unpatched workstation can provide attackers with an entry point into a broader enterprise environment. Rapid patch deployment, strong phishing defenses, and continuous monitoring remain essential for defending against modern exploit chains that combine browser vulnerabilities, privilege escalation techniques, and stealthy malware implants.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
