Volexity has linked Chinese APT group UTA0565 to a campaign chaining Chrome and Windows zero-days via spoofed media and NGO sites. Successful exploitation drops a custom payload called CLEANGULP. http

Volexity has linked Chinese APT group UTA0565 to a campaign chaining Chrome and Windows zero-days via spoofed media and NGO sites. Successful exploitation drops a custom payload called CLEANGULP. https://www. volexity.com/blog/2026/09/21/m ind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Volexity has linked Chinese APT group UTA0565 to a campaign chaining Chrome and Windows zero-days via spoofed media and NGO sites. Successful exploitation drops a custom payload called CLEANGULP. http

mastodon:infosec-exchangeother7d ago kagi ↗

Volexity has linked Chinese APT group UTA0565 to a campaign chaining Chrome and Windows zero-days via spoofed media and NGO sites. Successful exploitation drops a custom payload called CLEANGULP. https://www. volexity.com/blog/2026/09/21/m ind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/