thehackernews.com 9 Sept 2026, 16:34 UTC

Chrome Zero-Day Chain BlueMoon Drops Espionage Backdoors on Windows

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
🇨🇳 APT31

FOUR espionage-linked clusters are openly deploying a previously undocumented Chrome/Windows exploit chain, dubbed BlueMoon, within days of each other. The first attribution goes to APT31 (China-aligned) on 28 August 2026, with subsequent activity from other clusters likely linked to China, though some usage remains unattributed. The kit chains together vulnerabilities in Google Chrome's V8 engine and Windows, enabling code execution and then local privilege escalation to drop payloads.

The attack starts with phishing emails that lure targets to actor-controlled URLs, where BlueMoon triggers, downloads a loader, installs a Chrome extension‑like component, and then uses DLL sideloading and other techniques to install backdoors such as GemStone and ShadowPad variants, depending on the cluster.

The exploit chain relies on three vulnerabilities: CVE-2026-85046 (a type confusion in V8), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google patched the 85046 flaw; Microsoft addressed 85880 in its September 2026 Patch Tuesday.

Evidence from Proofpoint describes multiple variant forms and campaign-specific landing pages, while CISA added the Chrome flaw to its Known Exploited Vulnerabilities list on 4 September, with federal agencies told to patch by 18 September. After exploitation, the kit uses reflectively loaded DLLs to fingerprint the host, elevate privileges, and fetch additional payloads, including remote executables via curl.

Practically, organisations should scan for indicators such as chrome[.]exe spawning cmd[.]exe then curl[.]exe, files named ChromeUpdate[.]exe or msgbox[.]exe in TEMP, and specific registry, mutex, and scheduled task artefacts noted by Proofpoint.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline