EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

Editorial source
Editorial OSINT source. The content is an indication to verify with independent institutional or technical sources before operational decisions.
EudorIA operational summary

What it means

Priority 85/100

UTA0565, un attore cinese, ha sfruttato una catena di zero-day in Chrome e Windows per distribuire il malware CLEANGULP. Le attacchi sono stati rilevati il 3 e 4 settembre 2026, utilizzando siti falsi e phishing. Il malware ha capacità di esecuzione remota e comunicazione C2 su HTTP.

Why it matters

La PMI italiana è a rischio di attacchi mirati da attori esteri, con potenziale accesso a dati sensibili e danni operativi. La distribuzione di malware avanzato potrebbe compromettere la reputazione e la continuità operativa.

Potential operational benefits

  • Riduzione della superficie esposta alle vulnerabilità
  • Miglioramento della visibilità e controllo su attività sospette
  • Protezione contro accessi non autorizzati e malware avanzati
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMonitoraggio / SIEMMFA / IdentitàSegmentazione di rete
AudienceITSOCCISO
Information centre

Translation in progress

The Hacker News

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

Source
The Hacker News
Publishing entity
The Hacker News
Entity type
editorial osint
Area
Global
Original language
en · translation in preparation
Publication
23/09/2026 10:29
MITRE ATT&CK
T1190, T1078, T1486
CVE
CVE-2026-85046, CVE-2026-87491, CVE-2026-85880
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source