INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Nation-State Actors Exploit Zero-Day Flaws in Windows and Chrome

| 2026-09-10 14:11 CRITICAL HIGH
Executive Summary AI-generated
Researchers at enterprise cybersecurity company Proofpoint have observed the use of a spear phishing operation attributed to the JungleBamboo threat actor associated with China. The attackers, known for targeting NGOs in the US and other high-value targets, used BlueMoon deployments as part of their attacks. This critical incident highlights the ongoing threat posed by this threat actor, which has been linked to multiple zero-day vulnerabilities in Microsoft Windows and Google Chrome.
Technical Mitigations AI-generated
* Implement a patching and updating strategy for Windows and Chrome to ensure timely fixes of zero-day vulnerabilities, and regularly review software dependencies to minimize the risk of exploitation. * Use secure coding practices, such as input validation and sanitization, when developing applications that interact with web browsers or operating systems. * Conduct regular security audits and penetration testing to identify potential weaknesses in application code and infrastructure, and implement remediation measures promptly. * Educate users about phishing attacks and best practices for online safety, including avoiding suspicious links and attachments, and using strong passwords and two-factor authentication.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowPadShadowPad CVE-2026-87491CVE-2026-87491 CVE-2026-85880CVE-2026-85880 CVE-2026-85046CVE-2026-85046
Target & Sectors
ASEAN ASEAN NORTH_AMERICA NORTH_AMERICA aerospaceaerospace manufacturingmanufacturing governmentgovernment defensedefense
Incident Timeline
‎August 7
Threat actors exploited a previously unknown exploit kit within 12 days of the release of stable Chrome on September 3.
organisation Chromium
vulnerability CVE-2026-85046
‎August 28
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used to target US NGOs, mining companies, and physical commodity trading firms since August 28 in spearphishing operations attributed to the JungleBamboo threat actor associated with China.
source_region China
organisation JungleBamboo
organisation Violet Typhoon
tactic Phishing
target_region United States
organisation TA412
organisation the Association for Asian Studies
‎28 August 2026
The China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) exploited the BlueMoon exploit kit within 12 days of its initial deployment.
organisation JungleBamboo
organisation Violet Typhoon
target_region China
‎August 28, 2026
The China-aligned state-sponsored group APT31 exploited a Four Nation-State Actors Exploit Kit used within 12 days to target non-governmental organizations and physical commodity trading firms in the U.S.
source_region China
attribution JungleBamboo
attribution PerplexedGoblin
attribution RedBravo
attribution Violet Typhoon
tactic Phishing
organisation Google Gemini
‎September 1st
Threat actors used a previously unknown exploit kit to compromise multiple organizations within 12 days.
‎September 2
China's UNK_LateNight exploit kit was used to target US aerospace and defense companies within 12 days.
source_region China
source_region United States
industry Aerospace
industry Defense
organisation RFQ
‎September 2, 2026
Threat actors used spear-phishing lures to target multiple U.S. aerospace companies within 12 days, exploiting a GemStone backdoor that allowed them to issue commands through a command-and-control channel.
industry Aerospace
tactic Phishing
malware ShadowPad
target_region China
organisation GemStone
industry Manufacturing
target_region Viet Nam
organisation Cloudflare Workers
organisation UNK_DoubleCheck (
‎2026/09/02
Threat actors exploited CVE-2026-85880, a previously patched vulnerability, within 12 days of its patching by Microsoft.
vulnerability CVE-2026-85046
vulnerability CVE-2026-85880
organisation Microsoft
organisation Google
organisation CVE-2026
‎September 3
Threat actors used Exploit Kit to target government, consulting, and financial organizations in Indonesia and Singapore within 12 days of the fix being committed to the Chromium source tree on August 7.
industry Government
target_region Indonesia
target_region Singapore
organisation Chromium
vulnerability CVE-2026-85046
‎September 3, 2026
Threat actors used a Four Nation-State Actors Exploit Kit to target government, consulting, and financial sector organizations in Indonesia and Singapore within 12 days.
tactic Phishing
target_region China
industry Government
target_region Indonesia
target_region Singapore
‎4 September
Threat actors exploited the Chrome vulnerability using a Four Nation-State Actors Exploit Kit within 12 days.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎2026/09/09
Nation-state actors exploited a threat actor group known as BlueMoon, using the Exploit Kit within 12 days.
source_region China
tactic Espionage
organisation BlueMoon
‎September 10, 2026
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days.
tactic Espionage
infrastructure Windows
‎2026/09/10
The four nation-state actors used the same Chrome zero-day exploit kit, BlueMoon, within 12 days.
organisation DLL
infrastructure Windows
organisation Rust
organisation Microsoft Windows
organisation SecurityAffairs
organisation Chromium
organisation Chrome’s
organisation WebAssembly
organisation Chrome
organisation ALPC
organisation Windows Notification Facility
organisation Google Chrome
organisation Windows Advanced Local Procedure Call
organisation LPE
organisation Julia Paluch
organisation Stuart Del Caliz
organisation Mutex
organisation Dataupcheckinfo Registry
organisation TurboFan
organisation UTA0560
organisation Grimwedge
organisation JScript
organisation NFL
organisation CHANEL
organisation Nation-State Actors
organisation BlueMoon
organisation CVE
organisation Google
organisation GemStone
organisation Google Gemini
organisation Chrome, Edge, Brave
organisation Secure Preferences
organisation HMAC
organisation Cloudflare Worker
organisation Cloudflare R2
organisation DNS
organisation TXT
organisation Cloudflare Workers
data_breach 3 September
organisation CreateProcess
organisation Cloudflare R2 Bucket
organisation VRP
organisation CTF
‎September 2026
Threat actors exploited CVE-2026-85880, a newly discovered zero-day vulnerability in the Windows LPE component.
infrastructure Windows
vulnerability CVE-2026-85880
organisation Microsoft
vulnerability CVE-2026-85046
organisation Google
organisation CVE-2026
‎18 September
Threat actors exploited the Chrome flaw in the Four Nation-State Actors Exploit Kit within 12 days.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
3
September
Intelligence Sources