China-Linked Phish Uses Fake Sites to Exploit Chrome

CyberScoop · High sophistication
Last updated September 22, 2026

Researchers say a China-aligned group (UTA0565) sent phishing emails to government targets and used multiple fake websites to lure victims into visiting pages that triggered a Chrome-and-Windows zero-day exploit chain. The messages used political advocacy themes and spoofed well-known organizations to lower suspicion, then relied on unpatched software flaws to gain access.

Key findings

  • Volexity tracked a group it calls UTA0565 using phishing emails and multiple fake websites to deceive victims.
  • The lure content included a political/advocacy message urging targets to publicly support an imprisoned Hong Kong activist (Chow Hang-tung).
  • The group spoofed domains impersonating reputable organizations (Center for American Progress, China Digital Times).
  • Victims were targeted during a short window before Chrome/Microsoft vulnerabilities were disclosed or patched.
  • Volexity says UTA0565 used a payload from a previously undocumented malware family it calls “CLEANGULP.”

Who’s being targeted

  • Commonly targeted roles: Government affairs / policy teams, Executive leadership and executive assistants, Communications / public relations, Researchers/analysts who read external policy/news sites, IT/security teams responsible for rapid patching.
  • Affected industries: Government, Media, Corporate training/education services.
  • Attack channels: email, website.
  • Impersonated: A civic/advocacy campaign (email crafted to look legitimate); in other variants, reputable media/think-tank brands, Center for American Progress or China Digital Times.

Awareness takeaways

  • Treat advocacy/news emails that push you to click as suspicious, verify the sender and the URL using a trusted path before opening.
  • Don’t trust a webpage just because it looks legitimate; attackers can copy real content onto fake sites to lower your guard.
  • Fast patching matters: attackers may target a short window before fixes are widely deployed (“patch gap”).

Red flags to watch for

  • Emotionally charged political request designed to prompt quick action
  • Website is a lookalike/fake site used as a decoy
  • Message comes from a spoofed/impersonated domain rather than an official source
  • Sender domain is a spoof/lookalike of a trusted publisher/think tank
  • Link leads to a fake website even if the page content looks real
  • Timing/urgency pressures recipients to click before verifying
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Please publicly support imprisoned Hong Kong activist Chow Hang‑tung. Read the statement here.” Looks legit, right? But researchers at Volexity found a group called UTA0565 using emails like this, plus fake sites that copy real content, to silently exploit Chrome and Windows with a zero‑day chain called CLEANGULP. Here’s the twist: the page looks exactly like Center for American Progress or China Digital Times because it’s using their real content as a decoy, while hidden code hits unpatched Chrome and Windows in that tiny patch gap. If an advocacy or news email pushes you to click, don’t. Open your browser, type the organization’s URL yourself, and go there directly.

Similar attacks

Fake NGO Sites Lure Victims Into Chrome 0-Day Chain

Fake NGO Sites Lure Victims Into Chrome 0-Day Chain

China-linked actor UTA0565 sent phishing emails that pushed recipients to click spoofed links to fake media/NGO websites. Visiting the sites triggered a Chrome-to-Windows zero-day exploit chain that escaped the browser sandbox and installed CLEANGULP malware for remote control.

September 23, 2026
NGOs Lured via Donation Form Into Chrome 0-Day Chain

NGOs Lured via Donation Form Into Chrome 0-Day Chain

Researchers reported two China-linked groups targeting NGOs with spear-phishing that led victims through a legitimate U.S. university website before redirecting them to attacker infrastructure. The attackers used a chained Chrome/Windows exploit to take control, then deployed different payloads,…

September 15, 2026
Spear-Phishing Link Triggers Chrome-Windows Exploit

Spear-Phishing Link Triggers Chrome-Windows Exploit

China-linked attackers targeted NGOs with spear-phishing emails that urged recipients to click a link to a legitimate U.S. university website. The link path abused a website flaw to silently redirect victims to attacker infrastructure, which then exploited Chrome and Windows to install malware…

September 15, 2026
BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

Researchers found multiple espionage groups using the same Chrome+Windows exploit kit (“BlueMoon”) within days of each other. The groups sent realistic phishing emails (internship requests, conference outreach, procurement inquiries, and vaccination appointments) that pushed victims to click links…

September 10, 2026
Trusted Channels Hijacked for Phishing and Malware

Trusted Channels Hijacked for Phishing and Malware

The article describes multiple real-world social engineering operations this week, including phishing sent from a legitimate Trezor newsletter channel and malware pushed through a verified HBO Max Reddit ad account. It also highlights a large-scale network of fake online stores impersonating real…

September 18, 2026
China-Linked Hackers Push “Gemini” Phish With Zero-Days

China-Linked Hackers Push “Gemini” Phish With Zero-Days

Proofpoint reports multiple China-aligned espionage groups used a chained set of browser/Windows zero-days (“BlueMoon”) and delivered it through phishing emails. Victims who clicked a phishing link could end up with a malicious browser extension disguised as Google Gemini, letting attackers watch…

September 11, 2026