ZeroHour

Search: “UNK_DoubleCheck”

2 stories

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Proofpoint reports four nation-state actors, mostly China-nexus, adopted the BlueMoon Chrome and Windows zero-day exploit kit within 12 days, targeting US organizations.

Proofpoint tracked an exploit kit dubbed BlueMoon that chains CVE-2026-85046, a Chrome V8 type-confusion bug, with an unnamed V8 sandbox escape and CVE-2026-85880, a Windows kernel privilege escalation using ALPC and the Windows Notification Facility. The first observed use was by China-nexus TA412 (APT31, Violet Typhoon, JungleBamboo) on August 28, 2026 against US NGOs, mining companies, and commodity trading firms, followed by UNK_LateNight targeting US aerospace and defense companies on September 2. Both V8 bugs were patch-gap zero-days: the fix was committed to Chromium on August 7 but reached stable Chrome on September 3, enabling rapid weaponization from public patches. TA412's post-exploitation payload, GemStone, is a malicious browser extension posing as an AI-powered Google Gemini companion that captures keystrokes, cookies, screenshots, and browsing history via a Cloudflare Worker C2.

Security Affairsupdated · 59m agofirst · 6d agoExploit / PoC in the wild 19 sourcesCVE-2026-85046CVE-2026-858801

Multiple Chinese hacking groups seen using identical Chrome zero-day exploit

Four China-linked espionage groups share identical BlueMoon Chrome zero-day exploit kit targeting US defense contractors and Asian government agencies.

Proofpoint identified at least four Chinese-aligned espionage groups (TA412/RedBravo, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket) using an identical Chrome zero-day exploit kit dubbed BlueMoon in late August through this week. Targets include US defense contractors, NGOs, mining companies, and Southeast Asian government agencies. The exploit chains a Chromium patch-gap vulnerability with a Windows flaw, delivering malware such as ShadowPad and a fake Gemini browser extension backdoor, with possible AI-assisted exploit development.

The Record · 7d agoExploit / PoC in the wild 2 sources1