INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Nation-State Actors Exploit Zero-Day Flaws in Windows and Chrome
| 2026-09-10 14:11 CRITICAL HIGHExecutive Summary AI-generated
Researchers at enterprise cybersecurity company Proofpoint have observed the use of a spear phishing operation attributed to the JungleBamboo threat actor associated with China. The attackers, known for targeting NGOs in the US and other high-value targets, used BlueMoon deployments as part of their attacks. This critical incident highlights the ongoing threat posed by this threat actor, which has been linked to multiple zero-day vulnerabilities in Microsoft Windows and Google Chrome.
Technical Mitigations AI-generated
* Implement a patching and updating strategy for Windows and Chrome to ensure timely fixes of zero-day vulnerabilities, and regularly review software dependencies to minimize the risk of exploitation.
* Use secure coding practices, such as input validation and sanitization, when developing applications that interact with web browsers or operating systems.
* Conduct regular security audits and penetration testing to identify potential weaknesses in application code and infrastructure, and implement remediation measures promptly.
* Educate users about phishing attacks and best practices for online safety, including avoiding suspicious links and attachments, and using strong passwords and two-factor authentication.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowPadShadowPad
CVE-2026-87491CVE-2026-87491
CVE-2026-85880CVE-2026-85880
CVE-2026-85046CVE-2026-85046
Target & Sectors
ASEAN
ASEAN
NORTH_AMERICA
NORTH_AMERICA
aerospaceaerospace
manufacturingmanufacturing
governmentgovernment
defensedefense
Incident Timeline
August 7
Threat actors exploited a previously unknown exploit kit within 12 days of the release of stable Chrome on September 3.
Click on any entity below to view its context and source!
organisation
Chromium
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, almost four weeks before it rolled into the stable Chrome release on September 3.
vulnerability
CVE-2026-85046
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, almost four weeks before it rolled into the stable Chrome release on September 3.
August 28
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used to target US NGOs, mining companies, and physical commodity trading firms since August 28 in spearphishing operations attributed to the JungleBamboo threat actor associated with China.
Click on any entity below to view its context and source!
source_region
China
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used since August 28 in spearphishing operations attributed to the JungleBamboo (a.k.a. APT31, Violet Typhoon, APT31, Tide Castle) threat actor associated with China.
organisation
JungleBamboo
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used since August 28 in spearphishing operations attributed to the JungleBamboo (a.k.a. APT31, Violet Typhoon, APT31, Tide Castle) threat actor associated with China.
organisation
Violet Typhoon
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used since August 28 in spearphishing operations attributed to the JungleBamboo (a.k.a. APT31, Violet Typhoon, APT31, Tide Castle) threat actor associated with China.
tactic
Phishing
Starting August 28, TA412 targeted US NGOs, mining companies, and physical commodity trading firms using phishing emails that posed as university students seeking internships or as outreach related to the Association for Asian Studies conference.
target_region
United States
Starting August 28, TA412 targeted US NGOs, mining companies, and physical commodity trading firms using phishing emails that posed as university students seeking internships or as outreach related to the Association for Asian Studies conference.
organisation
TA412
Starting August 28, TA412 targeted US NGOs, mining companies, and physical commodity trading firms using phishing emails that posed as university students seeking internships or as outreach related to the Association for Asian Studies conference.
organisation
the Association for Asian Studies
Starting August 28, TA412 targeted US NGOs, mining companies, and physical commodity trading firms using phishing emails that posed as university students seeking internships or as outreach related to the Association for Asian Studies conference.
28 August 2026
The China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) exploited the BlueMoon exploit kit within 12 days of its initial deployment.
Click on any entity below to view its context and source!
organisation
JungleBamboo
“The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026.
organisation
Violet Typhoon
“The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026.
target_region
China
“The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026.
August 28, 2026
The China-aligned state-sponsored group APT31 exploited a Four Nation-State Actors Exploit Kit used within 12 days to target non-governmental organizations and physical commodity trading firms in the U.S.
Click on any entity below to view its context and source!
source_region
China
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
attribution
JungleBamboo
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
attribution
PerplexedGoblin
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
attribution
RedBravo
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
attribution
Violet Typhoon
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
tactic
Phishing
A brief description of the observed attack chains is as follows -
APT31
(Beginning on August 28, 2026), which used spear-phishing lures to target non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the U.S. to trick victims into clicking on a malicious link that serves BlueMoon, which then downloads and runs a loader executable responsible for installing a malicious browser add-on disguised as Google Gemini using a
Chrome extension integrity bypass technique
called
GhostChrome-X
.
organisation
Google Gemini
A brief description of the observed attack chains is as follows -
APT31
(Beginning on August 28, 2026), which used spear-phishing lures to target non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the U.S. to trick victims into clicking on a malicious link that serves BlueMoon, which then downloads and runs a loader executable responsible for installing a malicious browser add-on disguised as Google Gemini using a
Chrome extension integrity bypass technique
called
GhostChrome-X
.
September 1st
Threat actors used a previously unknown exploit kit to compromise multiple organizations within 12 days.
September 2
China's UNK_LateNight exploit kit was used to target US aerospace and defense companies within 12 days.
Click on any entity below to view its context and source!
source_region
China
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
source_region
United States
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
industry
Aerospace
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
industry
Defense
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
organisation
RFQ
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
September 2, 2026
Threat actors used spear-phishing lures to target multiple U.S. aerospace companies within 12 days, exploiting a GemStone backdoor that allowed them to issue commands through a command-and-control channel.
Click on any entity below to view its context and source!
industry
Aerospace
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
tactic
Phishing
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
malware
ShadowPad
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
target_region
China
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
organisation
GemStone
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
industry
Manufacturing
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
target_region
Viet Nam
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
organisation
Cloudflare Workers
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
organisation
UNK_DoubleCheck
(
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
2026/09/02
Threat actors exploited CVE-2026-85880, a previously patched vulnerability, within 12 days of its patching by Microsoft.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85046
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
vulnerability
CVE-2026-85880
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
Microsoft
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
Google
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
CVE-2026
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
September 3
Threat actors used Exploit Kit to target government, consulting, and financial organizations in Indonesia and Singapore within 12 days of the fix being committed to the Chromium source tree on August 7.
Click on any entity below to view its context and source!
industry
Government
Since September 3, UNK_QuietRacket has targeted government, consulting, and financial organizations in Indonesia and Singapore with conference-themed lures.
target_region
Indonesia
Since September 3, UNK_QuietRacket has targeted government, consulting, and financial organizations in Indonesia and Singapore with conference-themed lures.
target_region
Singapore
Since September 3, UNK_QuietRacket has targeted government, consulting, and financial organizations in Indonesia and Singapore with conference-themed lures.
organisation
Chromium
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, almost four weeks before it rolled into the stable Chrome release on September 3.
vulnerability
CVE-2026-85046
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, almost four weeks before it rolled into the stable Chrome release on September 3.
September 3, 2026
Threat actors used a Four Nation-State Actors Exploit Kit to target government, consulting, and financial sector organizations in Indonesia and Singapore within 12 days.
Click on any entity below to view its context and source!
tactic
Phishing
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
target_region
China
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
industry
Government
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
target_region
Indonesia
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
target_region
Singapore
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
4 September
Threat actors exploited the Chrome vulnerability using a Four Nation-State Actors Exploit Kit within 12 days.
Click on any entity below to view its context and source!
attribution
Known Exploited
"
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on 4 September, giving U.S. federal civilian agencies until 18 September to patch.
tactic
T1588.006 - Vulnerabilities
"
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on 4 September, giving U.S. federal civilian agencies until 18 September to patch.
2026/09/09
Nation-state actors exploited a threat actor group known as BlueMoon, using the Exploit Kit within 12 days.
Click on any entity below to view its context and source!
source_region
China
"Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus," Proofpoint
said
in a report published today.
tactic
Espionage
"Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus," Proofpoint
said
in a report published today.
organisation
BlueMoon
"Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus," Proofpoint
said
in a report published today.
September 10, 2026
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days.
Click on any entity below to view its context and source!
tactic
Espionage
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Pierluigi Paganini
September 10, 2026
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days.
infrastructure
Windows
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Pierluigi Paganini
September 10, 2026
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days.
2026/09/10
The four nation-state actors used the same Chrome zero-day exploit kit, BlueMoon, within 12 days.
Click on any entity below to view its context and source!
organisation
DLL
The payload was
ShadowPad
, the modular backdoor extensively used by Chinese state groups, delivered through a DLL sideloading chain that creates a scheduled task named “EdgeCore_AutoUpdate” for persistence and unhooks 20 network monitoring functions to reduce visibility.
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
infrastructure
Windows
Attack chains making use of BlueMoon have been found to rely on phishing emails as a starting point to trick targets into visiting an actor-controlled URL that triggers the two V8 flaws in succession to achieve code execution and escape the browser sandbox, and then exploit the Windows local privilege escalation bug to inject shellcode that downloads multiple payloads depending on the threat cluster behind it.
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
“Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities.
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called
BlueMoon
that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
BlueMoon combines two security issues in Chromium-based browsers that allow remote code execution and sandbox escape with a kernel local privilege escalation in Windows.
The three flaws chained by the BlueMoon exploit kit are:
CVE-2026-85046
: a type-confusion flaw in Chrome’s V8 JavaScript engine that provides arbitrary memory access inside the V8 sandbox
CVE-2026-87491
: a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode
CVE-2026-85880
: a heap-based buffer overflow in Windows ALPC that allows local privilege escalation
Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it has been leveraged since 2025 and repackaged in BlueMoon.
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws.
“This - combined with the exploit targeting older Windows builds - suggests that the exploit creator repackaged an existing capability into the BlueMoon exploit kit.”
It fingerprints the system, exploits the Windows privilege elevation flaw to elevate the Chrome renderer, and injects into Chrome’s parent process to run an operator-selected command.
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use.
The kit includes a complete Chrome exploit chain that can escape the V8 sandbox and gain higher privileges on Windows.
The Windows LPE only targets older builds, including Windows 10 through 22H2, Windows Server 2019 and 2022, and Windows 11 21H2.
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week.
"
The exploit chain employs three vulnerabilities -
CVE-2026-85046
, a type confusion in V8 in Google Chrome
A V8 sandbox escape that does not have an assigned CVE identifier
CVE-2026-85880
, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC)
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
Process tree
: chrome.exe starting cmd.exe, then curl.exe, then msgbox.exe
File
: ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder
Folder
: C:\Users\Public\stomp_ext
Scheduled task
: EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup or GeForceService
Mutex
: Dataupcheckinfo
Registry key
: HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32
Proofpoint also published detection rules for the kit's JavaScript loader and its command-and-control traffic, numbered 2071919 through 2071924.
organisation
Rust
A fourth group, tracked as UNK_DoubleCheck, targeted Vietnamese manufacturing firms with an in-memory Rust loader, though the final payload couldn’t be retrieved for analysis.
organisation
Microsoft Windows
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
“Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities.
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called
BlueMoon
that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
organisation
SecurityAffairs
“The majority of observed BlueMoon usage is assessed to be China-aligned espionage-motivated activity, although there is not sufficient evidence to attribute BlueMoon usage exclusively to China-aligned threat actors at the time of writing.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, BlueMoon)
organisation
Chromium
"Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers.
BlueMoon combines two security issues in Chromium-based browsers that allow remote code execution and sandbox escape with a kernel local privilege escalation in Windows.
organisation
Chrome’s
The three flaws chained by the BlueMoon exploit kit are:
CVE-2026-85046
: a type-confusion flaw in Chrome’s V8 JavaScript engine that provides arbitrary memory access inside the V8 sandbox
CVE-2026-87491
: a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode
CVE-2026-85880
: a heap-based buffer overflow in Windows ALPC that allows local privilege escalation
Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it has been leveraged since 2025 and repackaged in BlueMoon.
CVE-2026-85046
is a type-confusion bug in Chrome’s V8 JavaScript engine that abuses an optimization flaw in the TurboFan JIT compiler: by mutating an array mid-sort, an attacker gets the ability to read object memory addresses and forge fake object pointers, building toward arbitrary read and write inside V8’s heap.
organisation
WebAssembly
The three flaws chained by the BlueMoon exploit kit are:
CVE-2026-85046
: a type-confusion flaw in Chrome’s V8 JavaScript engine that provides arbitrary memory access inside the V8 sandbox
CVE-2026-87491
: a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode
CVE-2026-85880
: a heap-based buffer overflow in Windows ALPC that allows local privilege escalation
Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it has been leveraged since 2025 and repackaged in BlueMoon.
then overwrites WebAssembly compiled function bodies with attacker shellcode from memory.
organisation
Chrome
It fingerprints the system, exploits the Windows privilege elevation flaw to elevate the Chrome renderer, and injects into Chrome’s parent process to run an operator-selected command.
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
Interestingly, both V8 vulnerabilities in Chrome are said to have been "patch-gap" zero-days at the time they were maliciously exploited.
organisation
ALPC
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
organisation
Windows Notification Facility
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
organisation
Google Chrome
"
The exploit chain employs three vulnerabilities -
CVE-2026-85046
, a type confusion in V8 in Google Chrome
A V8 sandbox escape that does not have an assigned CVE identifier
CVE-2026-85880
, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC)
organisation
Windows Advanced Local Procedure Call
"
The exploit chain employs three vulnerabilities -
CVE-2026-85046
, a type confusion in V8 in Google Chrome
A V8 sandbox escape that does not have an assigned CVE identifier
CVE-2026-85880
, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC)
organisation
LPE
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
organisation
Julia Paluch
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
organisation
Stuart Del Caliz
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
organisation
Mutex
Process tree
: chrome.exe starting cmd.exe, then curl.exe, then msgbox.exe
File
: ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder
Folder
: C:\Users\Public\stomp_ext
Scheduled task
: EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup or GeForceService
Mutex
: Dataupcheckinfo
Registry key
: HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32
Proofpoint also published detection rules for the kit's JavaScript loader and its command-and-control traffic, numbered 2071919 through 2071924.
organisation
Dataupcheckinfo
Registry
Process tree
: chrome.exe starting cmd.exe, then curl.exe, then msgbox.exe
File
: ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder
Folder
: C:\Users\Public\stomp_ext
Scheduled task
: EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup or GeForceService
Mutex
: Dataupcheckinfo
Registry key
: HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32
Proofpoint also published detection rules for the kit's JavaScript loader and its command-and-control traffic, numbered 2071919 through 2071924.
organisation
TurboFan
CVE-2026-85046
is a type-confusion bug in Chrome’s V8 JavaScript engine that abuses an optimization flaw in the TurboFan JIT compiler: by mutating an array mid-sort, an attacker gets the ability to read object memory addresses and forge fake object pointers, building toward arbitrary read and write inside V8’s heap.
organisation
UTA0560
The second hacker group is UTA0560, which targeted NGOs using donation lures and triggered an infection chain that delivered Grimwedge, an in-memory JScript backdoor for reconnaissance, file and process management, command execution, and payload uploads.
organisation
Grimwedge
The second hacker group is UTA0560, which targeted NGOs using donation lures and triggered an infection chain that delivered Grimwedge, an in-memory JScript backdoor for reconnaissance, file and process management, command execution, and payload uploads.
organisation
JScript
The second hacker group is UTA0560, which targeted NGOs using donation lures and triggered an infection chain that delivered Grimwedge, an in-memory JScript backdoor for reconnaissance, file and process management, command execution, and payload uploads.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Nation-State Actors
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days.
organisation
BlueMoon
Proofpoint is tracking the exploit kit used in this activity as BlueMoon.”
organisation
CVE
A V8 sandbox escape (no CVE assigned, Chrome doesn’t issue CVEs for sandbox escapes)
organisation
Google
The kit repeatedly mentions Google’s V8CTF vulnerability bounty program.
organisation
GemStone
TA412’s post-exploitation payload was GemStone, a malicious browser extension that masquerades as an “AI-powered browsing companion by Google Gemini.”
organisation
Google Gemini
TA412’s post-exploitation payload was GemStone, a malicious browser extension that masquerades as an “AI-powered browsing companion by Google Gemini.”
organisation
Chrome, Edge, Brave
It installs into Chrome, Edge, Brave, and Vivaldi by bypassing the browser’s Secure Preferences protection mechanism using the same HMAC computation method the browser itself uses to validate extensions.
organisation
Secure Preferences
It installs into Chrome, Edge, Brave, and Vivaldi by bypassing the browser’s Secure Preferences protection mechanism using the same HMAC computation method the browser itself uses to validate extensions.
organisation
HMAC
It installs into Chrome, Edge, Brave, and Vivaldi by bypassing the browser’s Secure Preferences protection mechanism using the same HMAC computation method the browser itself uses to validate extensions.
organisation
Cloudflare Worker
It runs its C2 through a Cloudflare Worker domain.
organisation
Cloudflare R2
Its payload downloaded a Rust-based loader from Cloudflare R2 that staged a second DLL sideloading chain for C2.
organisation
DNS
Its C2 uses Google’s DNS-over-HTTPS service to resolve addresses through TXT records, then decrypts them with ChaCha20 before reaching Cloudflare Workers.
organisation
TXT
Its C2 uses Google’s DNS-over-HTTPS service to resolve addresses through TXT records, then decrypts them with ChaCha20 before reaching Cloudflare Workers.
organisation
Cloudflare Workers
Its C2 uses Google’s DNS-over-HTTPS service to resolve addresses through TXT records, then decrypts them with ChaCha20 before reaching Cloudflare Workers.
data_breach
3 September
This suggests the developers focused on releasing the exploit before the September 3 Chrome patch rather than making it difficult to detect.
organisation
CreateProcess
With those additional privileges, a separate injector shellcode injects a CreateProcess stub into the parent Chrome broker process, executing an operator-specified command.
organisation
Cloudflare R2 Bucket
The malware, for its part, contacts a Cloudflare R2 Bucket to fetch and execute a second DLL sideloading pair.
organisation
VRP
This is also bolstered by repeated references to the
v8CTF
challenge, an exploit-focused vulnerability reward program (VRP) and capture-the-flag (CTF) competition run by Google targeting the V8 engine.
organisation
CTF
This is also bolstered by repeated references to the
v8CTF
challenge, an exploit-focused vulnerability reward program (VRP) and capture-the-flag (CTF) competition run by Google targeting the V8 engine.
September 2026
Threat actors exploited CVE-2026-85880, a newly discovered zero-day vulnerability in the Windows LPE component.
Click on any entity below to view its context and source!
infrastructure
Windows
CVE-2026-85880, the Windows LPE component of the chain, is the same vulnerability Microsoft patched as an actively exploited zero-day in September 2026 Patch Tuesday.
vulnerability
CVE-2026-85880
CVE-2026-85880, the Windows LPE component of the chain, is the same vulnerability Microsoft patched as an actively exploited zero-day in September 2026 Patch Tuesday.
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
Microsoft
CVE-2026-85880, the Windows LPE component of the chain, is the same vulnerability Microsoft patched as an actively exploited zero-day in September 2026 Patch Tuesday.
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
vulnerability
CVE-2026-85046
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
Google
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
CVE-2026
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
18 September
Threat actors exploited the Chrome flaw in the Four Nation-State Actors Exploit Kit within 12 days.
Click on any entity below to view its context and source!
attribution
Known Exploited
"
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on 4 September, giving U.S. federal civilian agencies until 18 September to patch.
tactic
T1588.006 - Vulnerabilities
"
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on 4 September, giving U.S. federal civilian agencies until 18 September to patch.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
BlueMoon combines two security issues in Chromium-based browsers that allow remote code execution and sandbox escape with a kernel local privilege escalation in Windows.
The three flaws chained by the BlueMoon exploit kit are:
CVE-2026-85046
: a type-confusion flaw in Chrome’s V8 JavaScript engine that provides arbitrary memory access inside the V8 sandbox
CVE-2026-87491
: a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode
CVE-2026-85880
: a heap-based buffer overflow in Windows ALPC that allows local privilege escalation
Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it has been leveraged since 2025 and repackaged in BlueMoon.
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws.
“This - combined with the exploit targeting older Windows builds - suggests that the exploit creator repackaged an existing capability into the BlueMoon exploit kit.”
It fingerprints the system, exploits the Windows privilege elevation flaw to elevate the Chrome renderer, and injects into Chrome’s parent process to run an operator-selected command.
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Pierluigi Paganini
September 10, 2026
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days.
“Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities.
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use.
The kit includes a complete Chrome exploit chain that can escape the V8 sandbox and gain higher privileges on Windows.
CVE-2026-85880, the Windows LPE component of the chain, is the same vulnerability Microsoft patched as an actively exploited zero-day in September 2026 Patch Tuesday.
The Windows LPE only targets older builds, including Windows 10 through 22H2, Windows Server 2019 and 2022, and Windows 11 21H2.
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called
BlueMoon
that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
Attack chains making use of BlueMoon have been found to rely on phishing emails as a starting point to trick targets into visiting an actor-controlled URL that triggers the two V8 flaws in succession to achieve code execution and escape the browser sandbox, and then exploit the Windows local privilege escalation bug to inject shellcode that downloads multiple payloads depending on the threat cluster behind it.
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week.
"
The exploit chain employs three vulnerabilities -
CVE-2026-85046
, a type confusion in V8 in Google Chrome
A V8 sandbox escape that does not have an assigned CVE identifier
CVE-2026-85880
, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC)
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
Process tree
: chrome.exe starting cmd.exe, then curl.exe, then msgbox.exe
File
: ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder
Folder
: C:\Users\Public\stomp_ext
Scheduled task
: EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup or GeForceService
Mutex
: Dataupcheckinfo
Registry key
: HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32
Proofpoint also published detection rules for the kit's JavaScript loader and its command-and-control traffic, numbered 2071919 through 2071924.
Metrics
data_breach
3
September
This suggests the developers focused on releasing the exploit before the September 3 Chrome patch rather than making it difficult to detect.
Intelligence Sources
The Hacker News
2026-09-09
Security Affairs
2026-09-10
BleepingComputer
2026-09-10
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-11T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
49x
organisation
Identified Entity
JungleBamboo
entity
20x
timeline
Temporal Reference
August 28
date
12x
attribution
Attributing Entity
Longtale/GemStone
authority
6x
tactic
Cyber Operation Type
Phishing
tactic
5x
target region
Target Country
Viet Nam
country
4x
industry
Targeted Sector
Aerospace
sector
4x
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
3x
vulnerability
Exploited CVE
CVE-2026-85046
cve
2x
source region
Origin Country
China
country
Contextual Telemetry
Context Block
9 METRICS
general metric
Entities
1
entities
malware
Malware Payload
ShadowPad
tool
infrastructure
Affected Product
Windows
software
general metric
Cve-2026
87,491
cve-2026
general metric
V8 Sandbox Escape
85,880
v8 sandbox escape
general metric
Windows
10
windows
general metric
Network
20
network
data breach
September
3
september
general metric
Vulnerabilities
85,046
vulnerabilities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.