BlueMoon exploit kit chains Chrome and Windows zero-days

A newly documented exploit kit dubbed BlueMoon is chaining recently fixed zero-day vulnerabilities in Google Chrome’s V8 JavaScript engine and the Microsoft Windows kernel to give espionage-focused threat actors one-click paths to SYSTEM-level access on targeted machines.[1][6][11][14]

Researchers at Proofpoint describe BlueMoon as a browser-based exploit chain that combines a type-confusion remote code execution bug in Chromium’s V8 engine, tracked as CVE-2026-85046, with a separate V8 sandbox escape, CVE-2026-87491, and a Windows Advanced Local Procedure Call (ALPC) heap overflow local privilege escalation flaw, CVE-2026-85880.[1][4][11][14][15] In observed attacks, a single click on a malicious link drives the victim’s browser to a booby-trapped page, executes arbitrary code inside the V8 engine, breaks out of the browser sandbox, and then exploits the Windows kernel bug to execute attacker-selected commands as SYSTEM on affected builds including 17763, 19041–19045, 20348 and 22000.[1][3][5][10]

BlueMoon’s impact is magnified by its rapid uptake among multiple state-aligned espionage actors, with Proofpoint and other vendors tracking at least four separate China-linked clusters deploying the same exploit kit within days of each other.[1][8][10][12][14] Campaigns attributed to groups such as TA412, also known as APT31, and other unnamed clusters have targeted NGOs, mining and commodity trading firms, aerospace manufacturers, financial institutions and government entities across the United States, Europe and Asia, underscoring how quickly a single exploit chain can become shared tradecraft in the cyber-espionage ecosystem.[8][10][12][13]

The BlueMoon activity also spotlights a widening “patch-gap” problem in the Chromium ecosystem, where fixes land in public source code weeks before they reach mainstream browsers used by most organizations.[1][4][5][11] Proofpoint’s timeline shows the change containing the fix for CVE-2026-85046 was committed to V8 on 7 August 2026, but did not reach the stable Chrome channel until 3 September, creating nearly a four-week window in which an exploit developer could reverse-engineer the patch and weaponize the bug against unpatched users.[1][4][5] During the same period, the Windows kernel vulnerability CVE-2026-85880 remained a true zero-day until Microsoft’s disclosure and patch release, making BlueMoon’s combined browser-and-kernel chain especially dangerous for organizations lagging on updates.[11][14][15]

In real-world attacks, BlueMoon has been delivered primarily via spearphishing emails that coax targets into clicking links to attacker-controlled pages hosting the exploit kit.[1][2][10][13] Once SYSTEM-level access is achieved, operators have deployed backdoors such as ShadowPad and Grimwedge, installed malicious browser extensions, and established persistence on compromised endpoints to support long-term intelligence collection, according to multiple threat intelligence reports.[2][6][8][13] SecurityWeek and other outlets note that the campaigns have been opportunistic and sometimes rushed, with different groups reusing the same infrastructure and tooling while tailoring lures and payloads to their own strategic objectives.[6][7][10]

Defenders are being urged to close the patch gap as quickly as possible by ensuring Chrome, Edge and other Chromium-based browsers are updated to the latest stable versions and by applying Microsoft’s fixes for CVE-2026-85880 across affected Windows builds.[1][4][11][14][15] Organizations should also tighten controls around email and web access, monitor for suspicious outbound connections and new browser extensions, and hunt for signs of post-compromise activity consistent with ShadowPad and similar implants, particularly in sectors that have already been singled out in BlueMoon campaigns.[2][6][8][13] The exploit kit’s rapid proliferation across unrelated espionage groups is a reminder that the window between upstream fixes and widely deployed patches is now a prime hunting ground for well-resourced adversaries — and that “patch later” remains a risky assumption.[1][5][11][14]

References

  1. Once in a BlueMoon: Multiple State-Aligned Threat Actors …
  2. China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
  3. BlueMoon turns the browser patch gap into a shared espionage capability — Security.io Daily
  4. Once in a BlueMoon: How a Chrome Patch-Gap Turned Three V8 Zero-Days Into an Espionage Kit
  5. BlueMoon: four separate state-nexus actor clusters independently weaponize a shared Chrome V8 + Windows kernel zero-day chain within one week
  6. BlueMoon Exploit Kit Chains Chrome and Windows Zero- …
  7. SecurityWeek: Cybersecurity News, Insights and Analysis
  8. BlueMoon Exploit Kit: Chinese APT Groups Chain Chrome and …
  9. BlueMoon: Four Spy Groups, One Chrome Exploit Kit – Gblock
  10. Attackers are weaponizing the gap between Chromium fixes and Chrome patches
  11. Multiple Chinese hacking groups seen using identical …
  12. BlueMoon exploit kit turns Chrome and Windows flaws into …
  13. Chinese espionage groups swarm to exploit triple-link chain …
  14. CVE-2026-85880 – Tenable

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply