Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [apt-group, threat-actor, espionage, china, chrome-zero-day] ยท confidence: low ยท affected_sectors: [defence, government, technology] ยท au_impact: true

UTA0560

UTA0560 is a threat-actor designation used by Proofpoint for a China-linked espionage cluster assessed as aligned with the People's Liberation Army's Ministry of State Security (MSS). It is one of the actors documented in September 2026 using the identical "BlueMoon" Chrome exploit kit against US defence contractors, NGOs, mining/commodity firms and Southeast Asian government agencies.

Attribution

Field Detail
Designation UTA0560 (Proofpoint "UTA" = Unattributed Threat Actor prefix)
Attributed by Proofpoint
Nexus China โ€” assessed MSS-aligned
Confidence Low โ€” internal vendor cluster label; public attribution is partial

Attribution caution: UTA0560 is an internal Proofpoint cluster designation, not a confirmed state-identity. As with most "UTA" (Unattributed Threat Actor) labels, the public record does not yet establish a firm government link โ€” the MSS alignment is Proofpoint's assessment. Confidence is kept low accordingly; this designation is best treated as a tracking tag pending further disclosure.

Activity in the BlueMoon campaign

  • Used the identical "BlueMoon" browser exploit chain (CVE-2026-85046 โ†’ CVE-2026-87491 โ†’ CVE-2026-85880) shared byte-for-byte with other China-linked clusters โ€” evidence of a common exploit supply chain or broker.
  • Post-exploitation payload: the GRIMWEDGE JScript backdoor.
  • Campaign observed from 1 September 2026 against US defence contractors, NGOs, mining/commodity firms and Southeast Asian government agencies.

TTPs

  • Browser zero-day chaining against Chrome for full remote compromise.
  • Patch-gap weaponisation: exploited a fix shipped upstream before reaching Chrome users.
  • JScript-based backdoor (GRIMWEDGE) for post-exploitation command and control.

Related Pages