What Is UTA0565 and How CLEANGULP Malware Operates

A Chinese state-linked threat actor tracked as UTA0565 has been caught chaining zero-day vulnerabilities to break into government networks and deploy a malware strain called CLEANGULP. Security researchers at Volexity identified the campaign after spotting the group combining flaws in Google Chrome and Microsoft Windows, allowing attackers to move from a browser exploit straight into full system compromise without needing the victim to download or open a suspicious file.

The attack chain reportedly relies on fake or compromised websites that lure targets into visiting a page controlled by the attackers. Once a vulnerable version of Chrome loads the page, the exploit chain triggers, escalates privileges through the Windows flaw, and quietly installs CLEANGULP. From there, the malware gives UTA0565 a foothold for espionage, data theft, or further lateral movement inside the target's network.

What makes this campaign notable is the use of a true zero-day chain: vulnerabilities that were unknown to Chrome and Windows developers at the time of exploitation, meaning no patch existed when the attacks began. That combination of stealth and speed is exactly why zero-day exploitation remains one of the most difficult threats for defenders to catch before damage is done.

Who's at Risk: Devices and Networks in the Blast Radius

Reporting on the campaign points to government entities, primarily in Asia, as the confirmed targets so far. But zero-day exploit chains built around widely used software like Chrome and Windows rarely stay confined to a single region or sector for long. Any organization or individual running unpatched versions of these platforms is technically exposed to the same exploit kit, even if they were not the original intended target.

This is particularly concerning for smaller government agencies, contractors, and NGOs that may lack the resources to monitor for nation-state level threats but still handle sensitive data that makes them attractive secondary targets. Everyday users are less likely to be directly targeted by an espionage-focused group like UTA0565, but they can still be caught in the crossfire if the same exploit kit gets reused, resold, or repurposed by other actors down the line.

A Familiar Pattern: Chinese APT Campaigns Keep Escalating

UTA0565 is not operating in isolation. Volexity's research notes that the exploit kit used in this campaign has appeared in the toolsets of multiple Chinese-aligned threat groups, suggesting shared infrastructure or overlapping resources between distinct advanced persistent threat (APT) operations. This mirrors a broader trend of China-linked groups running parallel espionage campaigns against government and diplomatic targets worldwide.

A recent example of this pattern is FamousSparrow's SparroWocky backdoor campaign, which targeted Latin American government institutions using a previously unreported piece of malware. Like UTA0565's CLEANGULP deployment, the SparroWocky operation shows how China-linked actors continue refining custom tools to maintain long-term access inside foreign government systems. Taken together, these campaigns suggest a coordinated, ongoing effort rather than a series of isolated incidents.

Defensive Steps: Patching, VPNs, and Malware Detection Basics

For organizations and individuals alike, UTA0565 zero-day exploit protection starts with the basics done consistently rather than perfectly:

  • Patch immediately when updates land. Zero-days lose their power the moment a fix is available. Delayed patching on Chrome, Windows, or any widely used software gives attackers a longer window to exploit known flaws even after they've gone public.
  • Enable automatic updates on browsers and operating systems wherever possible, especially on government and enterprise endpoints where manual patching cycles can lag.
  • Use a reputable VPN on untrusted networks. While a VPN will not stop a zero-day exploit chain by itself, it adds a meaningful layer of protection by encrypting traffic and masking network details that attackers sometimes use for reconnaissance before launching targeted attacks.
  • Deploy endpoint detection tools capable of flagging unusual process behavior, since zero-day malware like CLEANGULP often behaves anomalously even before it's formally identified by security vendors.
  • Restrict or monitor access to unfamiliar external websites on sensitive networks, particularly for staff who handle government or diplomatic data.

What This Means For You

If you work in government, defense, or any sector handling sensitive geopolitical data, this campaign is a reminder that patch management is not optional, it's frontline defense. For everyday users, the takeaway is simpler: keep your browser and operating system updated, and treat unfamiliar links with caution even when they appear on legitimate-looking sites. UTA0565 zero-day exploit protection isn't just a concern for IT departments; it reflects a broader security discipline that benefits anyone browsing the web on outdated software.

Staying Ahead of the Next Campaign

UTA0565's use of chained zero-days to deploy CLEANGULP malware fits a clear pattern of Chinese state-linked groups probing government networks around the world with increasingly sophisticated tools. This is unlikely to be the last such campaign. Readers interested in how these operations evolve can look at the FamousSparrow SparroWocky backdoor attacks for another recent example of the same broader playbook in action. Staying informed, patching promptly, and layering defenses like VPN use and endpoint monitoring remain the most practical ways to reduce exposure as these espionage campaigns continue to surface.