Fake NGO Sites Lure Victims Into Chrome 0-Day Chain

The Hacker News · High sophistication
Last updated September 23, 2026

China-linked actor UTA0565 sent phishing emails that pushed recipients to click spoofed links to fake media/NGO websites. Visiting the sites triggered a Chrome-to-Windows zero-day exploit chain that escaped the browser sandbox and installed CLEANGULP malware for remote control.

Key findings

  • UTA0565 used phishing emails and multiple fake websites that impersonated real media/NGO entities.
  • Phishing messages included spoofed links to lookalike domains that replicated legitimate sites and loaded extra hidden content via an iframe.
  • Clicking through led to a Chrome + Windows zero-day exploit chain that delivered a payload named "chrome_cleanup.exe" and installed CLEANGULP malware.
  • CLEANGULP used an HTTP command-and-control domain that mimicked a legitimate media brand (typosquatting).

Who’s being targeted

  • Commonly targeted roles: Government staff, Public affairs / communications, Executive assistants, Policy and research teams, Anyone handling external email and links.
  • Affected industries: Government, Non-profits/NGOs, Media and public policy organizations.
  • Attack channels: email, website.
  • Impersonated: Center for American Progress (CAP), China Digital Times.

Awareness takeaways

  • Treat advocacy or “please support/sign” emails as high-risk and verify the sender and destination site before clicking.
  • Train staff to spot lookalike domains and spelling mistakes (typosquatting), especially when the email claims to be a trusted media/NGO brand.
  • Assume “just visiting a website” can be enough to get infected; keep browsers/Windows fully patched and avoid clicking unknown links on high-value devices.

Red flags to watch for

  • Link goes to a lookalike domain (misspelling/odd TLD): americanprgoress[.]top
  • Email pushes urgent political action and external clicking
  • Website loads additional hidden content (not visible to the user)
  • Domain is not the expected legitimate site and uses an unusual TLD (.top)
  • The page is a replica designed to build trust
  • Unexpected download/compromise behavior after visiting the page
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Support Chow Hang-tung, sign the joint NGO letter.” Looks legit, even name-drops Center for American Progress. But the link goes to americanprgoress.top, a fake CAP site. Just visiting it can quietly trigger a Chrome-to-Windows zero-day chain and drop malware named chrome_cleanup.exe. Same trick with chinadigitaltimes.top. These cloned media and NGO sites load hidden iframes, then CLEANGULP malware phones home to a lookalike news domain over plain HTTP. If an advocacy or media email wants you to click, pause and hover: if the link isn’t the exact domain you expect, like americanprogress.org or chinadigitaltimes.net, do not open it.

Similar attacks

China-Linked Phish Uses Fake Sites to Exploit Chrome

China-Linked Phish Uses Fake Sites to Exploit Chrome

Researchers say a China-aligned group (UTA0565) sent phishing emails to government targets and used multiple fake websites to lure victims into visiting pages that triggered a Chrome-and-Windows zero-day exploit chain. The messages used political advocacy themes and spoofed well-known organizations…

September 22, 2026
Spear-Phishing Link Triggers Chrome-Windows Exploit

Spear-Phishing Link Triggers Chrome-Windows Exploit

China-linked attackers targeted NGOs with spear-phishing emails that urged recipients to click a link to a legitimate U.S. university website. The link path abused a website flaw to silently redirect victims to attacker infrastructure, which then exploited Chrome and Windows to install malware…

September 15, 2026
Spy Groups Phish Victims Into Chrome Exploit Kit

Spy Groups Phish Victims Into Chrome Exploit Kit

Researchers reported four separate espionage groups using the same “BlueMoon” exploit kit within days, targeting organizations in the US and Southeast Asia. The attacks began with phishing emails that lured recipients to attacker-controlled websites, where Chrome and Windows vulnerabilities were…

September 10, 2026
BlueMoon Phishing Uses Browser Zero-Days to Spy

BlueMoon Phishing Uses Browser Zero-Days to Spy

Multiple suspected China-linked espionage groups used a new exploit kit (“BlueMoon”) that starts with phishing emails and a malicious link to break into organizations in the US and Southeast Asia. Clicking the link can trigger browser and Windows vulnerabilities to install surveillance tools,…

September 9, 2026
Trusted Channels Hijacked for Phishing and Malware

Trusted Channels Hijacked for Phishing and Malware

The article describes multiple real-world social engineering operations this week, including phishing sent from a legitimate Trezor newsletter channel and malware pushed through a verified HBO Max Reddit ad account. It also highlights a large-scale network of fake online stores impersonating real…

September 18, 2026
Malicious Calendar Invites Surge With Malware Links

Malicious Calendar Invites Surge With Malware Links

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious…

September 18, 2026