PROOFPOINT threat researchers have tracked a new BlueMoon exploit kit used in espionage campaigns, chaining Chrome/Chromium browser flaws with a Windows kernel privilege escalation to breach targeted networks. The operation, active from late August into September 2026, involves spearphishing emails containing malicious links. When opened, the link leads to an attack chain that first exploits two Chromium vulnerabilities, then escapes the V8 sandbox, and finally uses a Windows kernel flaw to elevate privileges.
The two Chrome bugs cited are CVE-2026-85046 and a related type-confusion flaw, with patch evidence noting upstream fixes implemented in August 2026 and downstream stable updates issued by Google on 3 September 2026. The Windows kernel flaw is CVE-2026-85880. The report emphasises these were zero-days at the time of exploitation, and the threat actor converted public fixes into weaponised capabilities.
Proofpoint attributes observed activity to four espionage-oriented clusters with moderate-to-high confidence of Chinese state alignment: TA412 (APT31/Violet Typhoon), UNK_LateNight, UNK_QuietRacket, and UNK_DoubleCheck. TA412 reportedly deployed a browser extension named GemStone, while UNK_LateNight and UNK_QuietRacket delivered the ShadowPad backdoor and a Rust loader via the exploit chain, respectively.
The campaigns targeted US NGOs, defence and aerospace entities, and organisations in Southeast Asia, with notable intra-industry lures and compromised government accounts used to deliver emails. Impact ranges from credential theft and keystroke logging to network beacons and data exfiltration, with broader risk limited by the reliance on older Windows builds; modern Windows 11 systems are less susceptible to the kernel exploit.
Defence guidance calls for patching Chromium browsers, upgrading legacy Windows 10 hosts to Windows 11, auditing browser extensions, and blocking known command infrastructure endpoints.