BlueMoon Exploit Kit links current Chrome and Windows zero days

BlueMoon Exploit Kit links current Chrome and Windows zero days

Several spy groups have used a new exploit kit called BlueMoon in seemingly opportunistic and hasty operations, cybersecurity firm Proofpoint reports.

The China-linked APT Violet Typhoon (also known as APT31, JungleBamboo, TA412 and Tide Castle) was the first to use it on August 28th. Within days, several other Chinese threat actors began using it, but the activity may not have been limited to China-aligned groups.

“It is currently unknown how multiple different threat actors gained access to the exploit kit. Due to its ease of deployment, it is likely to become more widespread and adopted by espionage-motivated and financially motivated threat actors,” Proofpoint notes.

The BlueMoon The exploit kit was quickly adopted because it linked three vulnerabilities that were unpatched when it first emerged: two zero-day vulnerabilities in Chrome and one in Windows.

The Chrome bugs are tracked as CVE-2026-85046 and CVE-2026-87491 and will be fixed as zero-day patches on September 3 and September 8, respectively. Both affect the V8 JavaScript and WebAssembly engines.

The Windows zero day, tracked as CVE-2026-85880, was fixed on Patch Tuesday in September 2026. This is an escalation of rights in Windows Advanced Local Procedure Call (ALPC).

Advertising. Scroll to continue reading.

According to Proofpoint, BlueMoon exploits the V8 defects for sandbox escape, then fingerprints the host and executes the privilege escalation code. Next, a CreateProcess stub is injected into the parent Chrome broker process to download and run an executable via a curl command.

Proofpoint has identified several packaging variants of BlueMoon, all using the same underlying exploit chain and identical orchestration and loading mechanisms.

Retrieved development artifacts suggest that the creators of the exploit kit may have used AI to create it, “although no single artifact conclusively confirms this,” Proofpoint says.

BlueMoon was originally used by Violet Typhoon in attacks on NGOs in the US, as well as mining companies and physical commodity trading companies.

As of September 2, a second China-linked spy group tracked as UNK_LateNight used it against several U.S. aerospace companies, and a threat actor tracked as UNK_DoubleCheck targeted a manufacturing company in Vietnam.

The next day, Chinese spy group UNK_QuietRacket began using it in attacks against government, consulting and financial firms in Indonesia and Singapore.

“BlueMoon was quickly developed, deployed, and shared by multiple threat actors within days in a manner that yielded high detection signals. This may be due to lower costs and barriers to entry for this class of capabilities as AI agents increasingly enable the development of exploits for threat actors,” Proofpoint notes.

Related: North Korean hackers deploy new Linux spying toolkit

Related: Modified ScreenConnect clients used in a worm-like campaign

Related: AI Accelerates Malware Development, Not Its Success Rate: Analysis

Related: Rust supply chain attack linked to North Korean hackers

Leave a Reply

Your email address will not be published. Required fields are marked *