PROOFPOINT , with corroboration from Google Threat Intelligence, MSTIC and Volexity, identifies four espionage groups adopting a Chrome-and-Windows exploit kit named BlueMoon within roughly two weeks of its first appearance. The initial cluster, TA412 (aka JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE), a China-aligned actor linked to the MSS’s Hubei State Security Department, began targeting US NGOs, mining firms and a commodities trading company on 28 August 2026.
Subsequent clusters, including UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket, with suspected China nexus, expanded the targeting to aerospace and defence suppliers, a Vietnamese manufacturer, and government, consulting and financial organisations in Indonesia and Singapore. In each case, the chain used a Chrome exploit kit that combined multiple Chrome V8 and Windows vulnerabilities to escape the browser’s sandbox and execute a payload on Windows.
BlueMoon chains two CVEs in Chrome and one Windows Local Privilege Escalation to break out of the V8 sandbox, escalate privileges, and inject code into Chrome’s parent process. CVE-2026-85046 is a type-confusion bug in Chrome’s V8 engine exploited via a TurboFan JIT flaw; CVE-2026-85880 is a Windows kernel LPE using ALPC/NTF mechanisms. Evidence notes that both Chrome bugs were patch-gap zero-days at the time of observed activity, allowing rapid weaponisation after upstream patches were public.
The exploit kit’s default post-exploitation flow downloads an actor-provided executable and runs it via curl, with indicative logs and a markdown handover file suggesting AI-assisted development. Defenders should prioritise applying the September Chrome patch and the affected Windows patches (including CVE-2026-85880) across affected builds, and look for the kit’s operational indicators and cross-cluster similarities in activity.