Security

BlueMoon Exploit Kit Chains Three Chrome and Windows Zero Days, Four Espionage Groups Adopt It

Proofpoint and Volexity reported that four China aligned espionage groups used a shared BlueMoon exploit kit to chain three zero days in Chrome and Windows, exploiting a nearly four week patch gap.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 10, 2026 / Updated September 13, 2026 / 7 min read

Proofpoint and Volexity disclosed on September 9, 2026 that at least four espionage-motivated threat actors, most assessed as China-aligned, used a shared exploit kit called BlueMoon to chain three zero-days in Google Chrome and Microsoft Windows. The campaigns began on August 28, 2026, and exploited a patch gap between a Chromium source fix on August 7 and its arrival in stable Chrome on September 3. The three vulnerabilities are CVE-2026-85046, a type-confusion remote code execution flaw in Chromium's V8 JavaScript engine; CVE-2026-87491, a V8 sandbox escape; and CVE-2026-85880, a Windows kernel local privilege escalation flaw present in older Windows builds.

The BlueMoon kit represents a significant escalation in exploit sharing among state-aligned groups. Proofpoint identified four distinct clusters: TA412, also tracked as JungleBamboo, Violet Typhoon, APT31, and TIDE CASTLE; UNK_LateNight; UNK_DoubleCheck; and UNK_QuietRacket. Volexity independently tracked two Chinese threat actors, UTA0560 and JungleBamboo, using the same chain against different targets with different infrastructure. Both actors used byte-for-byte identical shellcode, suggesting a shared supply chain or exploit broker. The first observed cluster was TA412 on August 28, 2026, and within days several other clusters adopted BlueMoon.

The attacks targeted a diverse set of victims. TA412 targeted US NGOs, mining companies, and physical commodity trading firms, delivering a malicious Chrome extension posing as 'Google Gemini' tracked as GemStone. UNK_LateNight targeted US aerospace and defense-industrial-base companies from September 2, delivering the ShadowPad backdoor. UNK_DoubleCheck hit a Vietnamese manufacturer. UNK_QuietRacket targeted government, consulting, and financial organizations in Indonesia and Singapore from September 3. Volexity detected UTA0560 targeting several NGOs on September 1, abusing a reflected cross-site scripting flaw on a US university website to redirect victims to a multi-stage exploit chain.

The technical sophistication of BlueMoon includes features that suggest AI-assisted development. Proofpoint noted indicators such as extensive diagnostic logging, a referenced markdown handover document, and detailed debugging comments. The kit runs the exploit inside a Web Worker, retries up to five times, fingerprints the system, and injects into Chrome's parent process to run an operator-selected command. The default final command uses curl to save and run an executable under %TEMP%. These characteristics lower the barrier to entry for less skilled actors and enable rapid adaptation.

Key Facts

Proofpoint reported on September 9, 2026 that BlueMoon chains three vulnerabilities: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. CVE-2026-85046 is a type-confusion remote code execution flaw in Chromium's V8 JavaScript engine. CVE-2026-87491 is a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode. CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC that allows local privilege escalation. Volexity reported on September 9, 2026 that the chain exploited these same flaws and that both actors used byte-for-byte identical shellcode. The Chrome flaw was reported to Chromium on August 4, 2026, and fixed in the open-source codebase, but at the time of the attacks the fix had not reached a released version of Google Chrome, making it an effective zero-day against Chrome users.

The patch gap timeline is critical. The CVE-2026-85046 fix was committed to Chromium on August 7, 2026, and reached general stable Chromium on September 3, 2026, opening a nearly four-week window. Help Net Security reported on September 9, 2026 that Google fixed 230 vulnerabilities in Chrome, including CVE-2026-87491, which was the seventh actively exploited Chrome zero-day Google patched in 2026. The fix shipped in Chrome 153.0.8010.36 and .37 for Windows and macOS, and Chrome 153.0.8010.36 for Linux. Microsoft patched the Windows ALPC flaw CVE-2026-85880 in its September 2026 Patch Tuesday, which addressed 966 flaws on September 8. Google was reported to have fixed the earlier CVE-2026-85046 in a Chrome 152 stable update on September 4, 2026.

The threat actors and their tools are diverse. Proofpoint identified four espionage-motivated clusters. TA412, also known as JungleBamboo, Violet Typhoon, APT31, and TIDE CASTLE, targeted US NGOs, mining companies, and physical commodity trading firms from August 28, 2026. It delivered a malicious Chrome extension posing as 'Google Gemini' tracked as GemStone. UNK_LateNight targeted US aerospace and defense-industrial-base companies from September 2, delivering the ShadowPad backdoor. UNK_DoubleCheck hit a Vietnamese manufacturer. UNK_QuietRacket targeted government, consulting, and financial organizations in Indonesia and Singapore from September 3. Volexity detected UTA0560 targeting several NGOs on September 1, 2026, deploying the GRIMWEDGE JScript backdoor. JungleBamboo deployed SUPERSTOMP, which bypassed Chrome's encrypted-hash integrity protections to install LONGTALE, a credential-stealing Chrome extension masquerading as Google Gemini with extension ID ckiknalbeplpcpofpnabcnhjcegckfei.

BleepingComputer reported on September 10, 2026 that multiple cyber-espionage groups deployed BlueMoon, which combined two Chromium-based browser flaws with a Windows kernel local privilege escalation. The kit runs the exploit inside a Web Worker, retries up to five times, fingerprints the system, and injects into Chrome's parent process to run an operator-selected command. The default final command uses curl to save and run an executable under %TEMP%. Proofpoint said attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it had been used since 2025 and repackaged into BlueMoon. The LPE DLL compilation timestamp was from 2025 and did not appear forged. Proofpoint noted indicators consistent with AI-assisted development, including extensive diagnostic logging, a referenced markdown handover document, and detailed debugging comments. Proofpoint assessed that BlueMoon will likely proliferate further.

Analysis

What this really means is that the patch gap is becoming a primary attack vector for state-aligned espionage groups. The nearly four-week window between the Chromium source fix on August 7, 2026, and stable Chrome on September 3, 2026, allowed attackers to treat a publicly known fix as a zero-day. Volexity assessed with high confidence that patch-gap vulnerabilities pose greater risk as large language models make rapid vulnerability research and exploit development more accessible. The BlueMoon kit's rapid adoption by four distinct clusters within days, from August 28 to September 3, demonstrates that exploit sharing and reuse are accelerating. The fact that UTA0560 and JungleBamboo used byte-for-byte identical shellcode, despite operating with different infrastructure and targets, points to a common supply chain or exploit broker.

The bigger picture here is that advanced persistent threat groups are no longer developing exploits independently. They are purchasing or sharing access to a common toolkit, which lowers costs and speeds up operations. The AI-assisted development indicators reinforce this trend: tools that generate diagnostic logs and markdown handover documents make it easier for less sophisticated actors to deploy complex chains. The targeting profile shows a focus on espionage and intellectual property. US NGOs, mining companies, commodity trading firms, aerospace and defense contractors, and a Vietnamese manufacturer all represent strategic intelligence targets. The use of credential-stealing Chrome extensions masquerading as Google Gemini shows a shift toward browser-based persistence and data exfiltration. The specific extension ID ckiknalbeplpcpofpnabcnhjcegckfei provides a concrete indicator for defenders to hunt for.

The response from Google and Microsoft was swift once the flaws were public, but the damage was already done. Google fixed 230 vulnerabilities in Chrome, including CVE-2026-87491, and Microsoft patched CVE-2026-85880 in its September Patch Tuesday with 966 flaws. However, the initial patch gap remains a systemic issue. The fact that CVE-2026-85046 was reported to Chromium on August 4, 2026, and fixed on August 7, but not shipped to stable Chrome until September 3, highlights the lag between upstream source fixes and downstream user protection. Jihyeon Jeong of the Compsec Lab at Seoul National University reported CVE-2026-87491 on August 6, 2026, and earned a $2,500 bug bounty. This case shows that even when researchers report flaws promptly, the patch gap can still be exploited.

The BlueMoon campaign also highlights the role of third-party websites in exploit delivery. Volexity found that UTA0560 abused a reflected cross-site scripting flaw on a US university website to redirect victims to the exploit chain. This supply chain style attack complicates attribution and defense, as the university may not have been the intended target. The combination of browser and OS zero-days in a single kit means that endpoint protection alone may not be sufficient. Layered defenses, including browser isolation, timely patching, and network monitoring, are essential. The shared shellcode and identical indicators also mean that defenders who identify one campaign can potentially detect others by looking for the same patterns, such as the use of curl to run executables under %TEMP% or the GRIMWEDGE and SUPERSTOMP backdoors.

Why It Matters

The BlueMoon campaign demonstrates that state-aligned actors can rapidly operationalize zero-days when a patch gap exists. The adoption by four clusters within days, the majority with a suspected China nexus, shows that exploit kits are becoming commoditized. Organizations that rely on stable Chrome releases may be exposed for weeks even after a fix is available in source code. This risk is amplified for NGOs, defense contractors, and manufacturers that handle sensitive data. The targeting of US NGOs, mining companies, commodity trading firms, aerospace and defense firms, a Vietnamese manufacturer, and government and financial organizations in Indonesia and Singapore shows a broad and strategic focus on espionage and economic intelligence.

The use of AI-assisted development, as noted by Proofpoint, signals a new phase in exploit creation. Large language models can help identify vulnerabilities, generate debugging code, and produce documentation. Volexity's high confidence assessment that patch-gap risks will increase due to LLMs underscores the need for faster patch deployment and more proactive threat hunting. The shared shellcode also means that defenders who identify one campaign can potentially detect others by looking for the same indicators. The extension ID ckiknalbeplpcpofpnabcnhjcegckfei and the use of curl to run executables under %TEMP% are concrete artifacts that security teams can search for in their environments.

The targeting of a US university website with a reflected XSS flaw to redirect victims shows that attackers are leveraging third-party vulnerabilities to deliver exploits. This supply chain style attack on a university website complicates attribution and defense. The combination of browser and OS zero-days in a single kit means that endpoint protection alone may not be sufficient. Layered defenses, including browser isolation and timely patching, are essential. The fact that CVE-2026-85880 had likely been in use since 2025, based on the LPE DLL compilation timestamp, suggests that some zero-days may remain undetected for long periods before being repackaged into new exploit kits.

Next Up

Proofpoint assessed that BlueMoon will likely proliferate further. With Google and Microsoft having patched the flaws, the immediate window is closing, but other threat actors may adapt the kit or develop similar chains. The shared shellcode and AI-assisted development tools suggest that new variants could emerge quickly. Organizations should monitor for the specific indicators: the Chrome extension ID ckiknalbeplpcpofpnabcnhjcegckfei, the use of curl to run executables under %TEMP%, and the GRIMWEDGE and SUPERSTOMP backdoors. Google fixed 230 vulnerabilities in Chrome, including CVE-2026-87491, and Microsoft patched CVE-2026-85880 in its September Patch Tuesday with 966 flaws, but the patch gap phenomenon is unlikely to disappear, especially as LLMs accelerate vulnerability research.

Future exploit kits may chain even more zero-days across different platforms. The BlueMoon case shows that a single kit can combine browser and OS flaws to achieve full compromise. Defenders should prioritize rapid deployment of Chromium and Windows updates, and consider browser hardening measures. Volexity's report, authored by Ankur Saini, Conor Quigley, Sean Koessel, Steven Adair, and Tom Lancaster, and Proofpoint's report, crediting collaboration with Google Threat Intelligence Group, Microsoft Threat Intelligence Center, and Volexity, provide detailed indicators. The collaboration between these vendors also shows that cross-industry information sharing is critical for detecting and mitigating such threats.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.