The Hacker News (2026-09-23) covers Volexity’s follow-up on Chinese actor UTA0565: on Sep 3–4, while the bugs were still zero-days, the group used fake websites (spoofing media/NGO brands, including lookalikes of China Digital Times and Center for American Progress) to deliver the BlueMoon kit — Chrome CVE-2026-85046 and CVE-2026-87491 chained with Windows ALPC CVE-2026-85880 for sandbox escape and RCE. Payload: CLEANGULP (chrome_cleanup.exe) with shell/ps/upload/download/BOF over HTTP C2 mimicking a legitimate media domain. Volexity says the same kit appears across multiple Chinese actors — likely shared/customized, so observed cases understate scale.
Separately (Cyberinsider / Kaspersky GERT, 2026-09-22): a PAYLOAD incident at a Middle East manufacturer weaponized Active Directory Group Policy without encrypting Windows files. Initial access Apr 11 via compromised domain account on FortiGate SSL VPN; by Apr 13, domain-admin equivalent and a malicious GPO named “PAYLOAD” linked at the domain root — ransom note, wallpaper/lock-screen, login banner, disable built-in local admin — plus a second GPO (“win Firewall Off”) that disabled Windows Firewall. Policies reached endpoints Apr 13 and largely fired after reboots Apr 14. Data was exfiltrated and leaked; an ESXi PAYLOAD variant existed, but no Windows encryptor. Forensics found no persistent Windows malware — the attack lived inside AD.
Patch Chrome (and Chromium Edge) to current Stable and confirm Windows updates covering CVE-2026-85880. On the AD side: treat unexpected new GPOs, wallpaper changes, and mass local-admin/firewall disables as ransomware-class even when nothing is encrypted — remove bad GPOs from DCs before cleaning endpoints, restrict who can create/link domain-root GPOs, and put phishing-resistant MFA on VPN.