ZUBIQO.
AI & MLCryptoFinanceBig TechAI Models
CybersecurityGamingEVs & Clean EnergyRoboticsAerospaceBiotech & Health
Enterprise
ZUBIQO.

High-magnitude intelligence briefs for the tech and finance sectors. Zero fluff. Maximum signal.

[email protected]
X (Twitter)ThreadsTelegramBlueskyMastodon

Sections

  • AI & ML
  • Crypto
  • Finance
  • Big Tech
  • Cybersecurity
  • Gaming
  • EVs & Clean Energy
  • Robotics
  • Aerospace
  • Biotech & Health

Publication

  • About Us
  • Editorial Ethics
  • Partner With Us
  • Contact Us

Tools

  • AI Models Pricing

Legal

  • Privacy Policy
  • Terms of Service
  • Fair Use & DMCA

Disclaimer:Zubiqo Intelligence operates as a technology-enabled news and research publication under human editorial oversight. The news briefs, market analysis, "Magnitude Scores", and "Community Sentiment" metrics provided on this platform are strictly for informational and educational purposes only. They do not constitute financial, legal, investment, or trading advice. Cryptocurrencies and financial markets are highly volatile; always conduct your own research and consult with a licensed professional before making any investment decisions. By using this site, you agree to our Terms of Service.

© 2026 Zubiqo Intelligence. All rights reserved.

CybersecurityMAG 8Bearish
•
2026-09-23•1 min read

Chinese Hackers Weaponize Chrome-Windows Zero-Day Chain to Deliver CLEANGULP Malware

Zubiqo Take
QuoteThreads

"State-sponsored actors are now sharing fully weaponized, multi-stage zero-day kits like open-source libraries, making standard browser sandboxing effectively useless for high-value targets."

Chinese Hackers Weaponize Chrome-Windows Zero-Day Chain to Deliver CLEANGULP Malware
📷 Image Source: The Hacker News

Executive Summary

  • •Chinese hackers used a combined Chrome and Windows zero-day chain to execute remote code.
  • •The BlueMoon exploit kit linked CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to bypass sandboxes.
  • •Volexity warns the core exploit kit is being actively shared across multiple state-sponsored groups.

Community Sentiment

1-Tap Vote

Key Developments & Data

Chinese threat actor UTA0565 deployed a zero-day exploit chain on September 3 and 4, 2026, targeting Google Chrome and Microsoft Windows to achieve remote code execution. The attackers used the BlueMoon exploit kit to chain Chrome vulnerabilities CVE-2026-85046 and CVE-2026-87491 with Windows Advanced Local Procedure Call flaw CVE-2026-85880, breaking completely out of the browser's sandbox. Asian government entities were targeted with phishing emails masquerading as the Center for American Progress, directing victims to spoofed media and NGO domains. A hidden iframe on the fake sites executed the exploit chain and downloaded an executable named "chrome_cleanup.exe," installing the CLEANGULP malware built with Microsoft Visual C Compiler. The CLEANGULP payload establishes HTTP command-and-control communication through a hard-coded domain intentionally mimicking the non-profit media outlet The Conversation. "This seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese CNE community, where the core kit was likely shared, customized, and weaponized by multiple groups." — Volexity.
Zubiqo Intelligence Briefing

Get the unfiltered signal before markets open.

Top tech breakthroughs, venture funding, and market moves—synthesized into a 2-minute morning read. Zero PR fluff.

✓ 100% Free•✓ 1-click unsubscribe•✓ No spam ever

Zubiqo Strategic Assessment

Primary Impact

Asian government entities and organizations utilizing standard Google Chrome and Microsoft Windows environments without advanced runtime identity controls.

Strategic Shift

The rapid industrialization and operational sharing of sophisticated sandbox-escape zero-day kits among distinct Chinese state-sponsored cyber-espionage groups.

The Ripple Effect

Additional unmapped threat actors will likely be discovered utilizing variations of the BlueMoon exploit kit against broader global targets beyond the initial Asian government cluster.

This intelligence assessment is generated by Zubiqo's AI for informational purposes only.

Intelligence Quality Rating

Grade this brief: Drag the slider or tap a preset to score signal strength.

🔥High Impact75%
#cybersecurity#malware#zero-day#google#windows
Read original on The Hacker News
Zubiqo MethodologyVerified Signal

Synthesized across 1,500+ daily market sources with human editorial oversight under Zubiqo's standards.

Event Magnitude8 / 10
Share

Read Next

F5 BIG-IP Zero-Day: Critical RCE Flaw Exploited in the Wild
Cybersecurity

F5 BIG-IP Zero-Day: Critical RCE Flaw Exploited in the Wild

Cyera Secures $400M Goldman Sachs Extension at $12B Valuation
Cybersecurity

Cyera Secures $400M Goldman Sachs Extension at $12B Valuation

Stay on the wire

Breaking tech, AI, and market intelligence the moment it happens. Zero fluff.

Live Broadcasts
TelegramXThreadsBlueskyMastodon
OpenAI Codex Sandbox Shattered by Remote Code Execution Flaws
Cybersecurity

OpenAI Codex Sandbox Shattered by Remote Code Execution Flaws

ShinyHunters Breaches Rival Ransomware Gang Clop, Threatens 72-Hour Extortion Deadline
Cybersecurity

ShinyHunters Breaches Rival Ransomware Gang Clop, Threatens 72-Hour Extortion Deadline

Zubiqo Methodology

Verified Signal

Synthesized across 1,500+ daily market sources with human editorial oversight under Zubiqo's standards.

Event Magnitude8 / 10

Related Briefs

Cybersecurity

F5 BIG-IP Zero-Day: Critical RCE Flaw Exploited in the Wild

Sep 23
Cybersecurity

Cyera Secures $400M Goldman Sachs Extension at $12B Valuation

Sep 23
Cybersecurity

OpenAI Codex Sandbox Shattered by Remote Code Execution Flaws

Sep 21
Cybersecurity

ShinyHunters Breaches Rival Ransomware Gang Clop, Threatens 72-Hour Extortion Deadline

Sep 19