Chinese APTs Exploit Chrome and Windows Zero-Day Chain to Deploy CLEANGULP Malware Targeting Governments and NGOs

Chinese APTs Exploit Chrome and Windows Zero-Day Chain to Deploy CLEANGULP Malware Targeting Governments and NGOs

Executive Summary

In September 2026, multiple Chinese advanced persistent threat (APT) groups orchestrated a sophisticated campaign exploiting a zero-day vulnerability chain in Google Chrome and Microsoft Windows to deploy the highly modular CLEANGULP malware. This attack chain, observed in the wild by leading threat intelligence firms, leveraged a critical patch gap between the upstream Chromium source and the public release of Google Chrome, enabling attackers to achieve remote code execution and privilege escalation on fully patched Windows systems. The campaign targeted government entities, NGOs, and policy organizations, primarily in Asia and North America, using advanced spear-phishing techniques and a multi-stage exploitation framework. The deployment of CLEANGULP (also tracked as GRIMWEDGE) and the credential-stealing LONGTALE Chrome extension demonstrates a significant escalation in the operational sophistication and impact potential of Chinese cyber-espionage operations.

Threat Actor Profile

The campaign has been attributed to at least two Chinese APT groups: UTA0560 and JungleBamboo (also known as APT31, Violet Typhoon, or TA412). Both groups are known for their focus on cyber-espionage, targeting government, policy, and non-governmental organizations with advanced malware and credential theft operations. UTA0560 has a history of leveraging zero-day vulnerabilities and deploying custom backdoors for persistent access, while JungleBamboo is recognized for its use of browser-based credential theft and supply chain attacks. The observed sharing of exploit infrastructure and techniques between these groups suggests the involvement of a common exploit broker or a coordinated effort within the Chinese cyber threat ecosystem.

Technical Analysis of Malware/TTPs

The attack chain exploited three critical vulnerabilities: CVE-2026-85046 (Chrome V8 JavaScript Engine Type Confusion), CVE-2026-87491 (Chrome V8 WebAssembly sandbox escape), and CVE-2026-85880 (Windows Kernel Privilege Escalation via RtlpCreateServerAcl). The initial access vector was a spear-phishing email containing a link that abused a reflected XSS vulnerability on a legitimate university website, redirecting victims to attacker-controlled infrastructure. The exploit chain was delivered via a multi-stage JavaScript loader that fingerprinted the victim’s browser and operating system, ensuring only targeted systems were attacked.

Upon successful exploitation, the attackers achieved arbitrary read/write in the Chrome V8 sandbox, escaped the browser sandbox, and escalated privileges to SYSTEM on Windows. This allowed the injection of malicious code into the Chrome process and the download and execution of next-stage payloads.

UTA0560 deployed the GRIMWEDGE (CLEANGULP) JScript backdoor through a loader chain involving msgbox.exe (dropper), wsc.dll (sideloaded DLL), and a malicious MSI file. CLEANGULP established persistence via a scheduled task named "Windows Scheduled System" and communicated with command-and-control (C2) servers at cloud.shinewrist[.]net and ocr.opusaccel[.]top. Its capabilities included system reconnaissance, file and process management, arbitrary command execution, and file exfiltration.

JungleBamboo utilized the SUPERSTOMP loader to tamper with Chrome’s Secure Preferences and install the LONGTALE credential-stealing extension, masquerading as "Google Gemini" (extension ID: ckiknalbeplpcpofpnabcnhjcegckfei). LONGTALE harvested credentials, cookies, and session data, performed keylogging, captured screenshots based on keyword triggers, and supported remote command execution (excluding arbitrary code execution).

Exploitation in the Wild

The exploitation was first observed in early September 2026, with phishing campaigns targeting NGOs, government agencies, and policy organizations in Asia and the United States. The attackers exploited a patch gap, where vulnerabilities had been fixed in the Chromium source but were not yet available in the public Google Chrome release, allowing for a highly effective zero-day attack window. Victims were lured via spear-phishing emails referencing current events and redirected through legitimate but compromised websites to attacker infrastructure. The exploit chain was delivered through obfuscated JavaScript and HTML files, culminating in the deployment of CLEANGULP and LONGTALE. The campaign’s infrastructure included domains such as cloud.shinewrist[.]net, ocr.opusaccel[.]top, msbenefit[.]com, and gitprogram[.]com, with payloads hosted on attacker-controlled servers.

Victimology and Targeting

The primary targets of this campaign were government agencies, NGOs, and policy organizations with a focus on Asian and North American regions. The spear-phishing lures were tailored to current geopolitical events, increasing the likelihood of successful compromise among individuals involved in policy, advocacy, and research. The attackers demonstrated a high degree of operational security, using legitimate websites for redirection and carefully fingerprinting victims before delivering the exploit chain. The deployment of both a persistent backdoor (CLEANGULP) and a credential-stealing browser extension (LONGTALE) indicates a dual focus on long-term access and immediate data exfiltration.

Mitigation and Countermeasures

Organizations are strongly advised to ensure that all endpoints are running the latest versions of Google Chrome and Microsoft Windows, with all security patches applied as soon as they become available. Security teams should monitor for the presence of the following indicators of compromise: file hashes associated with CLEANGULP and LONGTALE, scheduled tasks named "Windows Scheduled System", and network connections to domains such as cloud.shinewrist[.]net, ocr.opusaccel[.]top, msbenefit[.]com, and gitprogram[.]com. Endpoint detection and response (EDR) solutions should be configured to detect DLL sideloading, unauthorized Chrome extension installations, and suspicious process injection activity. User awareness training should emphasize the risks of spear-phishing and the importance of verifying links, even when they appear to originate from trusted sources. Incident response teams should be prepared to conduct forensic analysis of compromised systems, focusing on browser process memory, scheduled tasks, and Chrome extension directories.

References

Volexity: Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows, The Hacker News, NVD - CVE-2026-85046, NVD - CVE-2026-85880, NVD - CVE-2026-87491

About Rescana

Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously monitor, assess, and mitigate cyber risks across their supply chain and digital ecosystem. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify and respond to emerging threats, ensuring robust protection for critical assets and sensitive data.

For further information or to discuss how Rescana can support your organization’s cybersecurity posture, please contact us at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.