
Fake NGO Sites Lure Victims Into Chrome 0-Day Chain
China-linked actor UTA0565 sent phishing emails that pushed recipients to click spoofed links to fake media/NGO websites. Visiting the sites triggered a Chrome-to-Windows zero-day exploit chain that escaped the browser sandbox and installed CLEANGULP malware for remote control.




