The website was a copy, and opening it was enough
Read americanprgoress[.]top slowly. The letters are in the wrong order, and in an email nobody would notice.
Volexity published the second part of its investigation on 21 September, and it lays out what a run of September patches was really for. A Chinese group it tracks as UTA0565 registered domains impersonating the Center for American Progress and China Digital Times, then built pages that pulled the genuine site into a hidden iframe so a visitor saw real content. Underneath, the page ran an exploit chain: two Chrome flaws, CVE-2026-85046 and CVE-2026-87491, to get code running inside the browser, then CVE-2026-85880 in the Windows Advanced Local Procedure Call service to break out of Chrome's sandbox and take the whole machine. Opening the page was the only step. Nothing to click, nothing to download, no prompt to approve.
The attacks ran on 3 and 4 September, while all three holes were still unpatched. The payload was a previously unknown family Volexity has named CLEANGULP. It arrived as chrome_cleanup.exe, installed itself as MicrosoftIME.exe inside the local AppData folder, and created a scheduled task called MicrosoftIME so it started again after every reboot. Its command server was thecovnresation[.]com, another scrambled spelling, this time of a real news site.
The targets were government bodies and media organisations in Asia rather than anyone reading this, and all three flaws are patched now. What should stick is the gap. Chrome's first fix shipped on 4 September and Windows closed the ALPC hole on 9 September, and a browser you have left open for two weeks is still running the old code no matter what the update page says. Close Chrome, reopen it, then check chrome://settings/help. Tendvane's app update check runs through winget and collects everything with a pending update into one list, which catches the programs that never nag.
Sources
- Volexity - Mind the (Patch) Gap, Part 2: fake websites used to deploy Chrome and Windows 0-day exploits
- CyberScoop - Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
- The Hacker News - Chinese hackers exploit Chrome-Windows zero-day chain to deploy CLEANGULP malware