Skip to content

CLEANGULP

CLEANGULP is a Windows backdoor used by the China-linked threat actor UTA0565 in targeted espionage operations against Asian government entities.

Profile source: Mallory opens in a new tab

CLEANGULP

Family profile

CLEANGULP is a Windows backdoor used by the China-linked threat actor UTA0565 in targeted espionage operations against Asian government entities. It was delivered through phishing lures and cloned websites that exploited chained Google Chrome remote-code-execution vulnerabilities, CVE-2026-85046 and CVE-2026-87491, together with the Windows local privilege-escalation vulnerability CVE-2026-85880. CLEANGULP establishes persistence through a scheduled task and uses encrypted, encoded HTTP command-and-control communications. It can execute shell commands, enumerate running processes, upload and download files, and execute additional operator-supplied code, including beacon object files. The malware is implemented in C and employs control-flow flattening and indirect calls to impede analysis.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 22, 2026
Last activity
Sep 22, 2026
Feed role
C2 / Distribution
Host form
0 IP / 2 hostnames

Reported operators

Threat actors

1 named in public reporting
UTA0565

Volexity said UTA0565 used a payload from a previously undocumented malware family it tracks as “CLEANGULP.”

Exploited software

Vulnerabilities linked to CLEANGULP

3 CVEs

MITRE ATT&CK

CLEANGULP in ATT&CK

14 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.