Chinese Threat Group Exploits Zero-Day Vulnerabilities in Chrome and Microsoft
Volexity researchers have identified another China-aligned threat group exploiting a chain of zero-day vulnerabilities in Chrome and Microsoft. The group, tracked as UTA0565, used the defects to target Asian government entities and media organizations between September 3 and 4, before patches were available.
The campaign's tactics differed from those observed by other Chinese espionage groups, which included using fake websites to deceive victims. Volexity shared phishing emails sent by UTA0565, including one that spoofed a domain impersonating the Center for American Progress.
The vulnerabilities exploited include CVE-2026-85046 and CVE-2026-87491 in Chromium-based browsers, as well as CVE-2026-85880 in Windows Advanced Local Procedure Call. This is not an isolated incident, as Proofpoint previously observed multiple state-aligned threat groups chaining the same vulnerabilities together since last August.
Volexity noted that UTA0565's use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns, both in exploitation mechanics and presentation to end users. The group used a payload from a previously undocumented malware family tracked as CLEANGULP.