BlueMoon Exploit Kit Reportedly Combines Chrome and Windows Zero-Days
Security researchers at Proofpoint report that several suspected espionage-focused threat groups have begun using a new exploit kit called BlueMoon, which combines recently disclosed vulnerabilities i...
Security researchers at Proofpoint report that several suspected espionage-focused threat groups have begun using a new exploit kit called BlueMoon, which combines recently disclosed vulnerabilities in Google Chrome and Microsoft Windows.
According to the company, the kit first appeared in attacks attributed to Violet Typhoon, a China-linked group also known as APT31, on August 28. Other clusters assessed to be linked to Chinese espionage activity reportedly adopted the tool within days. Proofpoint said it has not determined how the separate groups obtained the kit and cautioned that other financially motivated or state-aligned actors could also use it.
Exploit chain targets browser and operating system flaws
BlueMoon reportedly uses two Chrome zero-days, tracked as CVE-2026-85046 and CVE-2026-87491, affecting the V8 JavaScript and WebAssembly engine. Google addressed the flaws in updates released September 3 and September 8. The chain also includes CVE-2026-85880, a Windows Advanced Local Procedure Call privilege-escalation vulnerability patched by Microsoft in its September security updates.
Proofpoint said the Chrome vulnerabilities are used to escape browser protections before the kit profiles the device and attempts the Windows escalation. The activity then injects a process-creation component into Chrome's broker process, downloads an executable through a curl command, and runs it.
Targets span several industries and regions
The initial activity attributed to Violet Typhoon reportedly targeted US-based nongovernmental organizations, mining companies, and physical commodities trading firms. A separate cluster, identified as UNK_LateNight, was observed targeting US aerospace organizations beginning September 2. Other reported targets included a Vietnamese manufacturing organization and government, consulting, and financial-sector entities in Indonesia and Singapore.
Researchers identified multiple BlueMoon package variants but said they relied on the same exploit sequence and loading approach. Development artifacts suggested that artificial intelligence tools may have assisted in creating the kit, although Proofpoint said the evidence was not conclusive.
Organizations should apply current Chrome and Windows security updates, monitor browser-related process activity, and investigate unexpected command-line downloads or executions originating from Chrome processes.
