Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-22 · updated: 2026-09-22 · tags: [incident, government, phishing, zero-day] · confidence: high · severity: high · affected_sectors: [government] · au_impact: true

Volexity has documented a third Chinese threat actor, tracked as UTA0565, using the same chained zero-days it reported on 9 September from two other Chinese APTs — CVE-2026-85046 and CVE-2026-87491 in Google Chrome alongside CVE-2026-85880 in Windows — but with a different delivery technique. In campaigns run on 3–4 September, while the vulnerabilities were still unpatched, UTA0565 sent phishing emails linking to spoofed copies of legitimate websites rather than to attacker-branded infrastructure. One Chinese-language message to Asian government entities urged recipients to publicly support the imprisoned Hong Kong activist Chow Hang-tung and amplify her voice against Chinese Communist Party suppression of a June 4 commemoration; a second masqueraded as the Center for American Progress. The spoofed domains were chinadigitaltimes[.]top, imitating chinadigitaltimes.net, and americanprgoress[.]top, imitating americanprogress.org — the typo in the second is the attacker's, not this report's. At the time of analysis the fake China Digital Times site was no longer reachable, but a Censys search showed hosting IP 96.9.125[.]52 had served a copy designed to look identical to the legitimate site. The pattern is the notable part: the phishing page and the exploit chain are one operation, so a victim who trusts the domain is delivered straight into a zero-day.

Attribute Detail
Sector Government
Date 2026-09-22
Source Volexity
Reliability Tier 1
CVEs CVE-2026-85046, CVE-2026-85880, CVE-2026-87491