China-linked actor UTA0565 sent phishing emails that pushed recipients to click spoofed links to fake media/NGO websites. Visiting the sites triggered a Chrome-to-Windows zero-day exploit chain that escaped the browser sandbox and installed CLEANGULP malware for remote control.
Key findings
- UTA0565 used phishing emails and multiple fake websites that impersonated real media/NGO entities.
- Phishing messages included spoofed links to lookalike domains that replicated legitimate sites and loaded extra hidden content via an iframe.
- Clicking through led to a Chrome + Windows zero-day exploit chain that delivered a payload named "chrome_cleanup.exe" and installed CLEANGULP malware.
- CLEANGULP used an HTTP command-and-control domain that mimicked a legitimate media brand (typosquatting).
Who’s being targeted
- Commonly targeted roles: Government staff, Public affairs / communications, Executive assistants, Policy and research teams, Anyone handling external email and links.
- Affected industries: Government, Non-profits/NGOs, Media and public policy organizations.
- Attack channels: email, website.
- Impersonated: Center for American Progress (CAP), China Digital Times.
Awareness takeaways
- Treat advocacy or “please support/sign” emails as high-risk and verify the sender and destination site before clicking.
- Train staff to spot lookalike domains and spelling mistakes (typosquatting), especially when the email claims to be a trusted media/NGO brand.
- Assume “just visiting a website” can be enough to get infected; keep browsers/Windows fully patched and avoid clicking unknown links on high-value devices.
Red flags to watch for
- Link goes to a lookalike domain (misspelling/odd TLD): americanprgoress[.]top
- Email pushes urgent political action and external clicking
- Website loads additional hidden content (not visible to the user)
- Domain is not the expected legitimate site and uses an unusual TLD (.top)
- The page is a replica designed to build trust
- Unexpected download/compromise behavior after visiting the page
Read the video transcript
You get an email: “Support Chow Hang-tung, sign the joint NGO letter.” Looks legit, even name-drops Center for American Progress. But the link goes to americanprgoress.top, a fake CAP site. Just visiting it can quietly trigger a Chrome-to-Windows zero-day chain and drop malware named chrome_cleanup.exe. Same trick with chinadigitaltimes.top. These cloned media and NGO sites load hidden iframes, then CLEANGULP malware phones home to a lookalike news domain over plain HTTP. If an advocacy or media email wants you to click, pause and hover: if the link isn’t the exact domain you expect, like americanprogress.org or chinadigitaltimes.net, do not open it.