CLEANGULP is a Windows backdoor associated with China-linked threat actor UTA0565 and used in targeted cyber-espionage operations against Asian government entities. It was delivered following spear-phishing lures that directed victims to spoofed websites hosting a chained Chrome and Windows exploit sequence. The malware is a compiled, heavily obfuscated executable that establishes persistence through a scheduled task and communicates with operator-controlled infrastructure over encrypted HTTP. CLEANGULP supports arbitrary shell-command execution, running-process enumeration, file upload and download, and execution of additional operator-supplied beacon object files. Its functionality enables host reconnaissance, collection and exfiltration of files, and continued post-compromise operator control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Trois vulnérabilités critiques ont été enchaînées : CVE-2026-85046 : Type Confusion dans le moteur JavaScript V8 de Chrome.
CVE-2026-87491 : Échappement de sandbox WebAssembly dans Chrome V8.
CVE-2026-85880 : Élévation de privilèges noyau Windows via RtlpCreateServerAcl.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UTA0560 — CLEANGULP (alias GRIMWEDGE) : Backdoor JScript modulaire. Chaîne de chargement : msgbox.exe (dropper) → wsc.dll (DLL sideloadée) → fichier MSI malveillant. Persistance via tâche planifiée nommée “Windows Scheduled System”.
The payload is a malware family dubbed CLEANGULP, which is built using the Microsoft Visual C Compiler. It supports shell command execution, process listing, file upload/download, and execution of beacon object files.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
CLEANGULP (alias GRIMWEDGE) : Backdoor JScript modulaire ... Capacités : ... exécution de commandes arbitraires.
The malware was originally written in C and built using the Microsoft Visual C Compiler, then heavily obfuscated using control flow flattening and indirect calls to hinder analysis.
Installation to %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe ... Persistence through a scheduled task named “MicrosoftIME”.
“Each phishing message pointed to a domain controlled by the attackers that closely copied a legitimate site,” including pages impersonating China Digital Times and the Center for American Progress. CLEANGULP “installs itself under a Microsoft-looking name.”
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular JScript backdoor used by UTA0560. It performs system reconnaissance, file and process management, arbitrary command execution, and file exfiltration. It uses DLL side-loading and a scheduled task for persistence.
CLEANGULP is a Windows backdoor providing remote command execution, process enumeration, file upload and download, and beacon object file (BOF) execution. It communicates with a hard-coded HTTP command-and-control domain impersonating The Conversation.
Previously undocumented malware family deployed as a payload by the Chinese state-aligned UTA0565 group in phishing-led campaigns exploiting a triple chain of Chrome/Chromium and Windows zero-day vulnerabilities.
A previously undocumented Windows backdoor delivered through the UTA0565 browser-to-Windows exploit chain. It disguises itself under a Microsoft-like name, establishes persistence with a scheduled task, communicates with a hardcoded HTTP C2 server using encrypted messages, and supports command execution, process enumeration, file transfer, and execution of operator-supplied code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.