Chinese Actor UTA0565 Exploits Chrome and Windows Zero-Days in Two-Day Campaign
Élevé · The Hacker News ·
Exploité
Vérification: The item describes attacks and CVEs dated September 2026, which is in the future relative to the current date and therefore not verifiable as a real security event.
En bref
- UTA0565, a Chinese actor, exploited CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880.
- The campaign ran for two days (Sept. 3-4, 2026) using fake websites.
- Targets include Google Chrome, Microsoft Windows, and ALPC.
- CLEANGULP malware was deployed after a multi-stage exploit chain.
- K-12 districts should patch immediately and monitor for indicators.
On September 3 and 4, 2026, a Chinese state-linked intrusion set tracked as UTA0565 carried out a short but intense operation. They leveraged three previously unknown vulnerabilities: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. These affect Google Chrome, Microsoft Windows, and the ALPC (Advanced Local Procedure Call) interface. The actor chained these flaws to achieve code execution and then dropped a malware family called CLEANGULP.
The campaign relied on fraudulent websites that mimicked legitimate services. Victims were lured to these decoy pages during a 48-hour window. Once a user visited a malicious site, the exploit chain triggered automatically, requiring no additional user interaction beyond browsing. This drive-by approach makes it especially dangerous for schools where students and staff frequently visit a wide range of web resources.
K-12 districts in New Brunswick and elsewhere are at risk because Chrome and Windows are ubiquitous in classrooms and administrative offices. ALPC is a core Windows component used for inter-process communication, so a flaw there could allow privilege escalation across a network. If CLEANGULP gains a foothold, it could lead to data theft, ransomware staging, or persistent access to student information systems.
The two-day window suggests a targeted, time-limited campaign, but the actor may still be refining exploits. Google and Microsoft are likely working on patches, but until they are released and deployed, unpatched systems remain vulnerable. The use of zero-days means traditional signature-based defenses may not detect the initial compromise.
IT admins should watch for unusual ALPC traffic, unexpected Chrome crashes, and outbound connections to newly registered domains. Since CLEANGULP is the payload, threat hunters should look for its known indicators. Given the government sector focus, sharing threat intelligence with other districts and the provincial cyber security center is critical.
Immediate actions include applying any emergency vendor mitigations, blocking known malicious domains, and enforcing browser isolation or strict content filtering. As patches become available, prioritize them for high-value targets like student records and finance systems. Continuous monitoring for lateral movement and credential dumping is also advised.
À faire maintenant
- Apply emergency patches for CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 as soon as Google and Microsoft release them.
- Block or sinkhole known fake websites and domains associated with UTA0565; update web filtering rules.
- Enable enhanced logging for ALPC and Chrome process creation; hunt for CLEANGULP indicators.
- Isolate or restrict high-risk systems (e.g., student records, finance) until patches are verified.
- Conduct a compromise assessment for any system that visited suspicious sites on Sept. 3-4, 2026.
- Enforce least privilege and disable unnecessary ALPC endpoints where possible.
- Share IOCs with the New Brunswick Department of Education and other K-12 partners.
Références CVE
- CVE-2026-85046
- CVE-2026-87491
- CVE-2026-85880
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.