Volexity has documented a third Chinese threat actor, tracked as UTA0565, using the same chained zero-days it reported on 9 September from two other Chinese APTs — CVE-2026-85046 and CVE-2026-87491 in Google Chrome alongside CVE-2026-85880 in Windows — but with a different delivery technique. In campaigns run on 3–4 September, while the vulnerabilities were still unpatched, UTA0565 sent phishing emails linking to spoofed copies of legitimate websites rather than to attacker-branded infrastructure. One Chinese-language message to Asian government entities urged recipients to publicly support the imprisoned Hong Kong activist Chow Hang-tung and amplify her voice against Chinese Communist Party suppression of a June 4 commemoration; a second masqueraded as the Center for American Progress. The spoofed domains were chinadigitaltimes[.]top, imitating chinadigitaltimes.net, and americanprgoress[.]top, imitating americanprogress.org — the typo in the second is the attacker's, not this report's. At the time of analysis the fake China Digital Times site was no longer reachable, but a Censys search showed hosting IP 96.9.125[.]52 had served a copy designed to look identical to the legitimate site. The pattern is the notable part: the phishing page and the exploit chain are one operation, so a victim who trusts the domain is delivered straight into a zero-day.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-22 |
| Source | Volexity |
| Reliability | Tier 1 |
| CVEs | CVE-2026-85046, CVE-2026-85880, CVE-2026-87491 |