ZeroHour
GBHackerspublished ()ingested Divya1
Part of a story covered by 20 sources: “BlueMoon Exploit Kit: China-Linked Espionage Groups Chain Chrome V8 and Windows Zero-Days” — merged summary and timeline →

China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks

highExploit / PoC exploited in the wildimportance 80CVE-2026-85046CVE-2026-85880
AI summary · glm-5.3-flash

China-linked clusters deploy the BlueMoon kit chaining Chrome V8 CVE-2026-85046 and Windows LPE CVE-2026-85880 in espionage campaigns.

Proofpoint researchers identified BlueMoon, an exploit kit combining a V8 type-confusion RCE (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel privilege-escalation flaw (CVE-2026-85880), first observed August 28, 2026. At least four clusters adopted it, led by TA412 (also tracked as APT31/Violet Typhoon) and followed by UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, targeting aerospace, manufacturing, government, consulting, and financial sectors. The kit exploited a nearly four-week patch gap between the public Chromium commit (August 7) and stable rollout (September 3). TA412 delivered the GemStone Chrome extension masquerading as a Gemini companion, while other clusters deployed ShadowPad via DLL sideloading, a Rust loader, and DoH-based C2.

  • BlueMoon chains CVE-2026-85046 (V8 type confusion) and CVE-2026-85880 (Windows kernel LPE) for sandbox escape to SYSTEM-level access
  • TA412 installed GemStone, a malicious Chrome extension collecting keystrokes, cookies, and screenshots with valid HMAC values
  • UNK_LateNight delivered ShadowPad with an EdgeCore_AutoUpdate scheduled task; UNK_QuietRacket targeted Singapore and Indonesia
  • Proofpoint suggests the kit's debug logging and markdown handover document may indicate AI-assisted development
  • Public Chromium patch weaponized within a four-week patch gap before stable builds shipped the fix

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-85046
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046)

Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references.

Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints.

8.81% KEV PoC ×5
  • Google Chrome prior to 152.0.7977.82
  • Google Chromium V8 V8 engine versions bundled with Chrome prior to 152.0.7977.82
massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus…
CVE-2026-85880
Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation

CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain.

Do: Apply Microsoft's September 2026 security (cumulative) updates for each affected Windows 10 and Windows Server build, as no public PoC or workaround is documented; CISA's KEV listing (added 2026-09-08) triggers BOD 26-04 patching requirements for federal agencies, so prioritize accordingly. Give priority to hosts where unprivileged users can log in — RDS/VDI servers, jump boxes, shared workstations — and to internet-exposed Windows servers, since an ALPC local privilege escalation is a common component in exploit chains combining remote code execution or browser flaws with elevation to SYSTEM. Organizations unable to patch promptly should follow BOD 26-04 guidance for cloud services or restrict local access to affected hosts until updates are applied.

7.8<1% KEV
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows Server 2012, 2016, 2019, 2022
mass≈100M+ Windows installations (Windows 10 1607–22H2 on consumer/enterprise endpoints plus widely deployed Windows Server 2012–2022)

Indicators of compromiseAll →

TypeIndicatorContext
domainattcdn.comom Domain TA412 delivery and download domain September 2026 attcdn[.]com Domain TA412 delivery and download domain September 2026
domainmsbenefit.com.]com Domain TA412 delivery and download domain August 2026 msbenefit[.]com Domain TA412 delivery and download domain September 2026
domainsecboxes.com26c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA412 delivery and download domain August 2026 msb
domainworkers.devd URL August 2026 extension-management-portal.centerfjdr658.workers[.]dev Hostname GemStone browser extension C&C August 2026 exten
sha256353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA41
sha256779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096dploitation. Ioc TA412 Indicator Type Description First Seen 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d SHA256 driver-html.js(BlueMoon exploit JavaScript) August 2
sha2567d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f8228809fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03
sha256e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f0041f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16c
sha256ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b256 driver-html.js(BlueMoon exploit JavaScript) August 2026 ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a4
urlhttps://api-prod.secboxes[ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evid
urlhttps://download.secboxes[ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-
urlhttps://evidence.msbenefit[od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki
urlhttps://project.secboxes[n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://
urlhttps://recommendation-letter.secboxes[ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://
urlhttps://zki0y83.msbenefit[.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manage
Full article900 words · extracted from gbhackers.com · click to collapse

Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel privilege-escalation flaw to compromise targets in espionage campaigns.

This activity was first observed on August 28, 2026, and at least four threat clusters have adopted it, most of which are suspected to have ties to China.

The initial user of BlueMoon was TA412, also known as JungleBamboo, Violet Typhoon, APT31, and TIDE CASTLE.

This group has previously been linked to Chinese state-sponsored espionage operations and has targeted U.S. non-governmental organizations, mining firms, and physical commodity trading companies.

Within days of its initial observation, other clusters, including UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, began deploying the same exploit chain against targets in the aerospace, manufacturing, government, consulting, and financial sectors.

Chrome-to-Windows Exploit Chain

BlueMoon combines three vulnerabilities and execution stages to transition from a phishing link to code execution outside of Chrome’s renderer sandbox:

  • CVE-2026-85046, a V8 JavaScript engine type-confusion bug enabling remote code execution in Chromium-based browsers.
  • A V8 sandbox escape that allows attacker-controlled shellcode to execute beyond the browser renderer.
  • CVE-2026-85880, a Windows kernel local privilege escalation flaw used against older Windows builds.

The Chrome vulnerability is particularly concerning as a “patch-gap” zero-day. Although the relevant fix for the V8 vulnerability was committed to the public Chromium source code on August 7, it wasn’t incorporated into the stable Chromium build until September 3.

This created a nearly four-week window during which attackers could reverse-engineer the public patch and weaponize the flaw against users of stable Chrome and other Chromium-based browsers.

Attack Flow (Source: ProofPoint)
Attack Flow (Source: ProofPoint)

The V8 exploit exploits an optimization weakness involving `Array.prototype.sort()` and `Array.fill()`. By changing the element type of an array during a sort operation, BlueMoon tricks V8’s Maglev and TurboFan optimizing compilers into treating object references as small integers.

This creates an address leak that lets the exploit construct `addrof` and `fakeobj` primitives, ultimately achieving arbitrary read/write access within V8’s heap cage.

Next, BlueMoon corrupts WebAssembly module metadata to overwrite compiled function bodies with shellcode. A reconnaissance DLL loaded reflectively identifies the Windows version, build number, Chrome integrity level, and `kernelbase.dll` version before determining whether the target is suitable for local privilege escalation.

The local privilege escalation (LPE) component of BlueMoon targets specific older Windows versions: Windows 10 version 1809; Windows 10 versions 2004 through 22H2; Windows Server 2019 and 2022; and Windows 11 for version 21H2.

The exploit uses Advanced Local Procedure Call and Windows Notification Facility mechanisms to gain kernel read/write access and enable the `SeDebugPrivilege` in the Chrome renderer process.

Phishing email (Source: Proofpoint)
Phishing email (Source: Proofpoint)

With elevated privileges, BlueMoon injects shellcode into the parent Chrome broker process. The default launcher utilizes `curl` to download an executable, save it as `%TEMP%\msgbox.exe`, and execute it outside the browser sandbox. This behavior provides defenders with potentially high-confidence indications for endpoint detection.

TA412 employed BlueMoon to install GemStone, a malicious Chrome extension that masquerades as an AI-powered Google Gemini browsing companion.

This extension collects keystrokes, cookies, browser storage, navigation activity, active tab metadata, and screenshots. It also modifies Chromium Secure Preferences files with valid HMAC values, allowing the extension to install without triggering typical integrity protections.

UNK_LateNight targeted U.S. aerospace organizations with business-to-business and request-for-quotation lures. Its deployment of BlueMoon delivered ShadowPad through a DLL sideloading chain, created a scheduled task for persistence called EdgeCore_AutoUpdate, and communicated with command-and-control infrastructure over HTTPS.

Meanwhile, UNK_DoubleCheck used compromised Southeast Asian government email accounts to target a Vietnamese manufacturer and delivered a Rust-based in-memory loader.

UNK_QuietRacket focused on Singapore and Indonesia, using conference-themed phishing emails, and deployed a DLL sideloading chain that used DNS-over-HTTPS TXT records for command-and-control resolution.

Proofpoint noted that BlueMoon’s extensive debug logging, implementation comments, and references to a markdown handover document may suggest the kit was developed with AI assistance.

While this assessment remains unconfirmed, the exploit’s rapid adoption highlights how publicly visible Chromium patches can greatly reduce the time and expertise needed to operationalize browser exploitation.

Ioc

TA412
IndicatorTypeDescriptionFirst Seen
779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096dSHA256driver-html.js(BlueMoon exploit JavaScript)August 2026
ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782bSHA256BlueMoon exploit JavaScriptAugust 2026
7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288SHA256ChromeUpdate.exe (or msgbox.exe)August 2026
e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004SHA256dist.zipAugust 2026
353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98eeSHA256background.jsAugust 2026
secboxes[.]comDomainTA412 delivery and download domainAugust 2026
msbenefit[.]comDomainTA412 delivery and download domainSeptember 2026
attcdn[.]comDomainTA412 delivery and download domainSeptember 2026
recommendation-letter.secboxes[.]comHostnameTA412 BlueMoon exploit pageAugust 2026
asianstudies.secboxes[.]comHostnameTA412 BlueMoon exploit pageAugust 2026
materials-project.secboxes[.]comHostnameTA412 BlueMoon exploit pageAugust 2026
project.secboxes[.]comHostnameTA412 BlueMoon exploit pageAugust 2026
evidence.msbenefit[.]comHostnameTA412 BlueMoon exploit pageSeptember 2026
data.attcdn[.]comHostnameTA412 BlueMoon exploit pageSeptember 2026
hxxps://project.secboxes[.]com/ChromeUpdate.exeURLDownload URLAugust 2026
hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exeURLDownload URLAugust 2026
hxxps://download.secboxes[.]com:443/dist.zipURLDownload URLAugust 2026
hxxps://api-prod.secboxes[.]com:443/downloadURLDownload URLAugust 2026
hxxps://evidence.msbenefit[.]com/msgbox.exeURLDownload URLSeptember 2026
hxxps://zki0y83.msbenefit[.]com:443/feedURLDownload URLAugust 2026
extension-management-portal.centerfjdr658.workers[.]devHostnameGemStone browser extension C&CAugust 2026
extension-management-portal.kmjukilo-lkjh.workers[.]devHostnameGemStone browser extension C&CSeptember 2026

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/