China-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
China-linked clusters deploy the BlueMoon kit chaining Chrome V8 CVE-2026-85046 and Windows LPE CVE-2026-85880 in espionage campaigns.
Proofpoint researchers identified BlueMoon, an exploit kit combining a V8 type-confusion RCE (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel privilege-escalation flaw (CVE-2026-85880), first observed August 28, 2026. At least four clusters adopted it, led by TA412 (also tracked as APT31/Violet Typhoon) and followed by UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, targeting aerospace, manufacturing, government, consulting, and financial sectors. The kit exploited a nearly four-week patch gap between the public Chromium commit (August 7) and stable rollout (September 3). TA412 delivered the GemStone Chrome extension masquerading as a Gemini companion, while other clusters deployed ShadowPad via DLL sideloading, a Rust loader, and DoH-based C2.
- BlueMoon chains CVE-2026-85046 (V8 type confusion) and CVE-2026-85880 (Windows kernel LPE) for sandbox escape to SYSTEM-level access
- TA412 installed GemStone, a malicious Chrome extension collecting keystrokes, cookies, and screenshots with valid HMAC values
- UNK_LateNight delivered ShadowPad with an EdgeCore_AutoUpdate scheduled task; UNK_QuietRacket targeted Singapore and Indonesia
- Proofpoint suggests the kit's debug logging and markdown handover document may indicate AI-assisted development
- Public Chromium patch weaponized within a four-week patch gap before stable builds shipped the fix
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85046 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046) Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references. Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints. | 8.8 | 1% | KEV PoC ×5 |
| massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus… | |
| CVE-2026-85880 | Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain. Do: Apply Microsoft's September 2026 security (cumulative) updates for each affected Windows 10 and Windows Server build, as no public PoC or workaround is documented; CISA's KEV listing (added 2026-09-08) triggers BOD 26-04 patching requirements for federal agencies, so prioritize accordingly. Give priority to hosts where unprivileged users can log in — RDS/VDI servers, jump boxes, shared workstations — and to internet-exposed Windows servers, since an ALPC local privilege escalation is a common component in exploit chains combining remote code execution or browser flaws with elevation to SYSTEM. Organizations unable to patch promptly should follow BOD 26-04 guidance for cloud services or restrict local access to affected hosts until updates are applied. | 7.8 | <1% | KEV |
| mass≈100M+ Windows installations (Windows 10 1607–22H2 on consumer/enterprise endpoints plus widely deployed Windows Server 2012–2022) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | attcdn.com | om Domain TA412 delivery and download domain September 2026 attcdn[.]com Domain TA412 delivery and download domain September 2026 |
| domain | msbenefit.com | .]com Domain TA412 delivery and download domain August 2026 msbenefit[.]com Domain TA412 delivery and download domain September 2026 |
| domain | secboxes.com | 26c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA412 delivery and download domain August 2026 msb |
| domain | workers.dev | d URL August 2026 extension-management-portal.centerfjdr658.workers[.]dev Hostname GemStone browser extension C&C August 2026 exten |
| sha256 | 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee | 3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee SHA256 background.js August 2026 secboxes[.]com Domain TA41 |
| sha256 | 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d | ploitation. Ioc TA412 Indicator Type Description First Seen 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d SHA256 driver-html.js(BlueMoon exploit JavaScript) August 2 |
| sha256 | 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 | 09fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03 |
| sha256 | e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 | 1f82288 SHA256 ChromeUpdate.exe (or msgbox.exe) August 2026 e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 SHA256 dist.zip August 2026 353b5bd2780c1b0c07c1283d83cf16c |
| sha256 | ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b | 256 driver-html.js(BlueMoon exploit JavaScript) August 2026 ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b SHA256 BlueMoon exploit JavaScript August 2026 7d6f6dcb17a4 |
| url | https://api-prod.secboxes[ | ad.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api-prod.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evid |
| url | https://download.secboxes[ | ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://download.secboxes[.]com:443/dist.zip URL Download URL August 2026 hxxps://api- |
| url | https://evidence.msbenefit[ | od.secboxes[.]com:443/download URL Download URL August 2026 hxxps://evidence.msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki |
| url | https://project.secboxes[ | n[.]com Hostname TA412 BlueMoon exploit page September 2026 hxxps://project.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps:// |
| url | https://recommendation-letter.secboxes[ | ecboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe URL Download URL August 2026 hxxps:// |
| url | https://zki0y83.msbenefit[ | .msbenefit[.]com/msgbox.exe URL Download URL September 2026 hxxps://zki0y83.msbenefit[.]com:443/feed URL Download URL August 2026 extension-manage |
Full article900 words · extracted from gbhackers.com · click to collapse
Researcher has discovered a rapidly spreading exploit kit called BlueMoon, which combines vulnerabilities in the Chrome browser with a Windows kernel privilege-escalation flaw to compromise targets in espionage campaigns.
This activity was first observed on August 28, 2026, and at least four threat clusters have adopted it, most of which are suspected to have ties to China.
The initial user of BlueMoon was TA412, also known as JungleBamboo, Violet Typhoon, APT31, and TIDE CASTLE.
This group has previously been linked to Chinese state-sponsored espionage operations and has targeted U.S. non-governmental organizations, mining firms, and physical commodity trading companies.
Within days of its initial observation, other clusters, including UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket, began deploying the same exploit chain against targets in the aerospace, manufacturing, government, consulting, and financial sectors.
Chrome-to-Windows Exploit Chain
BlueMoon combines three vulnerabilities and execution stages to transition from a phishing link to code execution outside of Chrome’s renderer sandbox:
- CVE-2026-85046, a V8 JavaScript engine type-confusion bug enabling remote code execution in Chromium-based browsers.
- A V8 sandbox escape that allows attacker-controlled shellcode to execute beyond the browser renderer.
- CVE-2026-85880, a Windows kernel local privilege escalation flaw used against older Windows builds.
The Chrome vulnerability is particularly concerning as a “patch-gap” zero-day. Although the relevant fix for the V8 vulnerability was committed to the public Chromium source code on August 7, it wasn’t incorporated into the stable Chromium build until September 3.
This created a nearly four-week window during which attackers could reverse-engineer the public patch and weaponize the flaw against users of stable Chrome and other Chromium-based browsers.

The V8 exploit exploits an optimization weakness involving `Array.prototype.sort()` and `Array.fill()`. By changing the element type of an array during a sort operation, BlueMoon tricks V8’s Maglev and TurboFan optimizing compilers into treating object references as small integers.
This creates an address leak that lets the exploit construct `addrof` and `fakeobj` primitives, ultimately achieving arbitrary read/write access within V8’s heap cage.
Next, BlueMoon corrupts WebAssembly module metadata to overwrite compiled function bodies with shellcode. A reconnaissance DLL loaded reflectively identifies the Windows version, build number, Chrome integrity level, and `kernelbase.dll` version before determining whether the target is suitable for local privilege escalation.
The local privilege escalation (LPE) component of BlueMoon targets specific older Windows versions: Windows 10 version 1809; Windows 10 versions 2004 through 22H2; Windows Server 2019 and 2022; and Windows 11 for version 21H2.
The exploit uses Advanced Local Procedure Call and Windows Notification Facility mechanisms to gain kernel read/write access and enable the `SeDebugPrivilege` in the Chrome renderer process.

With elevated privileges, BlueMoon injects shellcode into the parent Chrome broker process. The default launcher utilizes `curl` to download an executable, save it as `%TEMP%\msgbox.exe`, and execute it outside the browser sandbox. This behavior provides defenders with potentially high-confidence indications for endpoint detection.
TA412 employed BlueMoon to install GemStone, a malicious Chrome extension that masquerades as an AI-powered Google Gemini browsing companion.
This extension collects keystrokes, cookies, browser storage, navigation activity, active tab metadata, and screenshots. It also modifies Chromium Secure Preferences files with valid HMAC values, allowing the extension to install without triggering typical integrity protections.
UNK_LateNight targeted U.S. aerospace organizations with business-to-business and request-for-quotation lures. Its deployment of BlueMoon delivered ShadowPad through a DLL sideloading chain, created a scheduled task for persistence called EdgeCore_AutoUpdate, and communicated with command-and-control infrastructure over HTTPS.
Meanwhile, UNK_DoubleCheck used compromised Southeast Asian government email accounts to target a Vietnamese manufacturer and delivered a Rust-based in-memory loader.
UNK_QuietRacket focused on Singapore and Indonesia, using conference-themed phishing emails, and deployed a DLL sideloading chain that used DNS-over-HTTPS TXT records for command-and-control resolution.
Proofpoint noted that BlueMoon’s extensive debug logging, implementation comments, and references to a markdown handover document may suggest the kit was developed with AI assistance.
While this assessment remains unconfirmed, the exploit’s rapid adoption highlights how publicly visible Chromium patches can greatly reduce the time and expertise needed to operationalize browser exploitation.
Ioc
| TA412 | |||
| Indicator | Type | Description | First Seen |
| 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d | SHA256 | driver-html.js(BlueMoon exploit JavaScript) | August 2026 |
| ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b | SHA256 | BlueMoon exploit JavaScript | August 2026 |
| 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288 | SHA256 | ChromeUpdate.exe (or msgbox.exe) | August 2026 |
| e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004 | SHA256 | dist.zip | August 2026 |
| 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee | SHA256 | background.js | August 2026 |
| secboxes[.]com | Domain | TA412 delivery and download domain | August 2026 |
| msbenefit[.]com | Domain | TA412 delivery and download domain | September 2026 |
| attcdn[.]com | Domain | TA412 delivery and download domain | September 2026 |
| recommendation-letter.secboxes[.]com | Hostname | TA412 BlueMoon exploit page | August 2026 |
| asianstudies.secboxes[.]com | Hostname | TA412 BlueMoon exploit page | August 2026 |
| materials-project.secboxes[.]com | Hostname | TA412 BlueMoon exploit page | August 2026 |
| project.secboxes[.]com | Hostname | TA412 BlueMoon exploit page | August 2026 |
| evidence.msbenefit[.]com | Hostname | TA412 BlueMoon exploit page | September 2026 |
| data.attcdn[.]com | Hostname | TA412 BlueMoon exploit page | September 2026 |
| hxxps://project.secboxes[.]com/ChromeUpdate.exe | URL | Download URL | August 2026 |
| hxxps://recommendation-letter.secboxes[.]com/ChromeUpdate.exe | URL | Download URL | August 2026 |
| hxxps://download.secboxes[.]com:443/dist.zip | URL | Download URL | August 2026 |
| hxxps://api-prod.secboxes[.]com:443/download | URL | Download URL | August 2026 |
| hxxps://evidence.msbenefit[.]com/msgbox.exe | URL | Download URL | September 2026 |
| hxxps://zki0y83.msbenefit[.]com:443/feed | URL | Download URL | August 2026 |
| extension-management-portal.centerfjdr658.workers[.]dev | Hostname | GemStone browser extension C&C | August 2026 |
| extension-management-portal.kmjukilo-lkjh.workers[.]dev | Hostname | GemStone browser extension C&C | September 2026 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/china-linked-hackers-exploit-chrome-and-windows-zero-days/