www.securityweek.com 12 Sept 2026, 11:10 UTC

Chrome Zero Days Fuel BlueMoon Exploit Kit’s Espionage Surge

Chrome Zero Days Fuel BlueMoon Exploit Kit’s Espionage Surge
CyberSIXT Evidence Panel Source marked as original reporting

BLUEMOON is an exploit kit that security researchers say was rapidly adopted by multiple espionage groups in opportunistic, rushed campaigns. The China-linked Violet Typhoon (also known as APT31, JungleBamboo, TA412 and Tide Castle) first deployed BlueMoon on 28 August, with several other Chinese threat actors following soon after.

Proofpoint notes that the kit’s spread appears driven by its ease of adoption and by the fact that it chained together three unpatched flaws: two zero-days in Google Chrome (CVE-2026-85046 and CVE-2026-87491) and a Windows zero-day (CVE-2026-85880). The Chrome flaws affect the V8 JavaScript and WebAssembly engine, and the Windows flaw is an ALPC privilege-escalation issue fixed on September Patch Tuesday.

Proofpoint’s analysis describes a chain that exploits the Chrome vulnerabilities to escape the sandbox, fingerprints the host, and then triggers the Windows privilege escalation. A CreateProcess stub is injected into the Chrome broker process to download and execute a payload via a curl command. The kit was observed in different packaging variants but with the same underlying load chain and orchestration.

Development artefacts suggest AI may have been used in its construction, though no single artefact confirms this. BlueMoon was first seen targeting NGOs and mining entities in the US, and later used against a US aerospace company, a Vietnamese manufacturing organisation, and government, consulting and financial entities in Indonesia and Singapore as the campaign expanded.

Proofpoint emphasises the rapid, cross-actor sharing of BlueMoon and raises concerns that the ease of deployment could lower barriers for other espionage and financially motivated groups. Evidence includes observed deployments by Violet Typhoon, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket, with vulnerable targets spanning sectors and regions.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline