> Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
[AUTHOR: Matt Kapko]
[DATE: 22/09/2026 18:47]
[LANGUAGE: EN]
Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday.
The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said.
The timing of the malicious activity mirrors other spikes threat hunters observed and attributed to multiple Chinese espionage threat groups. Yet, Volexity noted UTA0565’s campaigns differed from those attacks by using multiple fake websites to deceive victims.
Volexity shared phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung. The group spoofed domains impersonating the Center for American Progress and China Digital Times in other phishing emails.
While UTA0565 showcased a variance in tactics, it used the same components researchers observed in previous instances of the exploit kit across multiple Chinese threat groups.
“This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese computer network exploitation community, where the core kit was likely shared, customized, and weaponized by multiple groups,” Volexity wrote in the blog post. “The activity reported so far reflects only two organizations’ observations; the full scope and impact are likely far broader.”
The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Sept. 8 in Windows Advanced Local Procedure Call.
Proofpoint, which previously observed multiple state-aligned threat groups chaining the vulnerabilities together in attacks since last August, said a limited group of organizations were exposed to all three vulnerabilities in a short window.
Proofpoint previously attributed attacks involving the zero-days to APT31, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket. At the time it warned that attackers of other origins and motivations could strike soon as well.
Volexity said UTA0565 used a payload from a previously undocumented malware family it tracks as “CLEANGULP.” Researchers also found several domains likely used by UTA0565 in similar campaigns targeting media organizations, halal restaurant search websites and corporate training organizations.
“UTA0565’s use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns observed by Volexity, both in the mechanics of the exploitation and the presentation to end users,” researchers wrote. “Using real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.”
The post Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects appeared first on CyberScoop.