Chinese threat actor UTA0565 exploited a Chrome-Windows zero-day chain to deploy CLEANGULP malware through fake websites impersonating media organizations and NGOs. Attacks targeting Asian government entities used phishing emails referencing Hong Kong activist Chow Hang-tung and spoofed the Center for American Progress. The malware supports remote command execution, file operations, and process enumeration via a C2 domain mimicking a legitimate media outlet.