arstechnica.com 9 Sept 2026, 20:55 UTC

BlueMoon Exploit Kit Races to Exploit Fresh Chrome and Windows Flaws

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
🇨🇳 APT31

PROOFPOINT reports that a chrome-and-windows exploit kit, dubbed BlueMoon, has been deployed rapidly by at least four groups after chaining three vulnerabilities to install malware of choice. The chain exploits two Chromium vulnerabilities in the V8 engine and a Windows kernel escalation, enabling remote code execution followed by system-level privileges. The first Chrome V8 flaw is CVE-2026-85046 and the Windows kernel bug is CVE-2026-85880; V8 sandbox escapes do not receive separate CVEs.

All three flaws had patches in the prior 24 hours, yet the kit was weaponised and widely disseminated before downstream updates could take effect. The analysis suggests the patch-gap across upstream Chromium patches and the accelerating discovery of vulnerabilities via AI contributed to the rapid, broad adoption.

The four groups named by Proofpoint so far are TA412 (China-aligned, indicted in 2024) targeting NGOs, mining companies and commodity traders in the US; UNK_LateNight (China-aligned) targeting US aerospace firms; UNK_DoubleCheck targeting a Vietnamese manufacturing entity; and UNK_QuietRacket hitting organisations in Singapore and Indonesia. The initial attack began on 28 August, with subsequent activity this month.

While the kit’s use is evident and patches exist, Proofpoint cautions that BlueMoon may continue to see renewed use as patched versions disseminate across Chromium-based browsers, given its lightweight adoption and low barrier to entry for actors with espionage or financial motives.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline