Volexity Flags China‑Aligned Group Exploiting Chrome and Microsoft Zero‑Days in Multi‑Stage Campaigns
Security research firm Volexity disclosed on Monday that a threat actor it tracks as UTA0565, a group with clear ties to Chinese state interests, has been leveraging a sophisticated chain of zero‑day vulnerabilities across Google Chrome and Microsoft software in a series of coordinated attacks.
The researchers describe the operation as a "triple‑link" exploitation sequence. Initial foothold is gained through an unpatched flaw in Chrome, which the group uses to deliver malicious payloads. Those payloads then pivot to a separate, previously unknown Microsoft vulnerability to elevate privileges, followed by a third zero‑day that secures persistence on the compromised host. The multi‑stage approach allows the attackers to move laterally and maintain long‑term access while evading many conventional defenses.
Volexity’s attribution to UTA0565 aligns with prior observations of Chinese‑aligned cyber units that focus on espionage and intellectual‑property theft. The group has surfaced in earlier reports for targeting sectors such as technology, aerospace, and critical infrastructure, often employing novel exploits to stay ahead of patch cycles. This latest activity underscores a pattern of using high‑impact, undisclosed vulnerabilities to achieve rapid infiltration before vendors can issue fixes.
The use of zero‑day exploits in both a browser and an operating‑system environment raises the stakes for defenders. Such vulnerabilities are typically reserved for nation‑state actors due to the resources required to discover and weaponize them. When deployed in the wild, they can compromise a wide range of organizations, from multinational corporations to government agencies, potentially exposing sensitive data and undermining trust in widely used software platforms.
Volexity urged enterprises to accelerate their patch management processes and to employ layered security controls, including behavior‑based detection and network segmentation, to mitigate the risk of similar multi‑vector attacks. The firm also indicated that it will continue monitoring the group’s activity, sharing indicators of compromise with the broader security community to help blunt future campaigns. The revelation adds to a growing catalog of state‑backed cyber operations that exploit zero‑days, highlighting the ongoing challenge of defending against adversaries with deep technical capabilities and direct access to advanced exploit research.
Comments (0)
Be the first to comment.
Join the discussion