BlueMoon Exploit Kit: China-Linked Espionage Groups Chain Chrome V8 and Windows Zero-Days
At least four China-aligned espionage groups rapidly adopted the BlueMoon kit, chaining Chrome zero-days CVE-2026-85046 and CVE-2026-87491 with Windows ALPC flaw CVE-2026-85880 to spy on government, defense, aerospace, NGO, and finance targets; Volexity…
Proofpoint identified a new exploit kit dubbed BlueMoon that chains a Chromium V8 type-confusion RCE (CVE-2026-85046), a V8/WebAssembly sandbox escape (CVE-2026-87491), and a Windows ALPC kernel privilege escalation (CVE-2026-85880) to achieve code execution, sandbox escape, and system privileges. First observed use was by China-nexus TA412 (Violet Typhoon/APT31/JungleBamboo) on August 28, 2026 against US NGOs, mining, and commodity trading firms; UNK_LateNight (US aerospace/defense, Sept 2), UNK_DoubleCheck (Vietnamese manufacturing), and UNK_QuietRacket (Indonesia/Singapore government, consulting, finance, Sept 3) adopted it within days. Both Chrome flaws were patch-gap zero-days — the fix landed in Chromium source around August 7 but only reached stable Chrome in early September — and the Windows LPE (which only works on Windows 10 and Server 2019/2022) was fixed in September Patch Tuesday. Volexity separately documented the same chain from September 1 used by UTA0560 (delivering the GRIMWEDGE JScript backdoor) and JungleBamboo (SUPERSTOMP loader installing the LONGTALE/GemStone fake Gemini credential-stealing extension), with byte-identical shellcode across the campaigns. Payloads also included ShadowPad via DLL sideloading and an in-memory Rust loader. Fewer than 20 victim organizations were directly observed, and researchers suspect AI-assisted exploit development from code artifacts, though without conclusive proof.
- BlueMoon chains three zero-days: CVE-2026-85046 (Chrome V8 type confusion RCE), CVE-2026-87491 (V8/WebAssembly sandbox escape), and CVE-2026-85880 (Windows ALPC privilege escalation; Proofpoint suspects the ALPC exploit existed since 2025).
- TA412 (Violet Typhoon/APT31/JungleBamboo) first used the kit on August 28, 2026 against US NGOs, mining, and commodity trading firms; UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket followed within days, targeting US aerospace/defense,…
- Volexity separately tracked UTA0560 and JungleBamboo using byte-identical exploit shellcode from September 1 against NGOs, with different payloads: GRIMWEDGE JScript backdoor for UTA0560 and SUPERSTOMP loader installing the LONGTALE…
- Volexity delivery abused reflected XSS on legitimate US university websites, serving hidden exploit iframes behind a donation-form image; Proofpoint observed phishing links, including lures posing as university interns and RFQs.
- The GemStone/LONGTALE browser extension masquerades as a Google Gemini AI companion, stealing cookies, session tokens, keystrokes (via keyword triggers), screenshots, and browsing history, with C2 via HTTP/Cloudflare; other payloads…
- Both Chrome bugs were patch-gap zero-days: fixes were committed to Chromium source on August 7, 2026 but shipped to stable Chrome only in early September (from September 3), giving attackers a roughly four-week window to weaponize publicly…
- The Windows LPE only affects Windows 10 and Server 2019/2022 and was patched in September 2026 Patch Tuesday; reports describe the bug as abusing ALPC and the Windows Notification Facility (Proofpoint) or RtlpCreateServerAcl (Volexity).
- Fewer than 20 victim organizations were directly observed by Proofpoint, with activity ongoing as of September 8; researchers expect the kit to proliferate to more actors, possibly including criminal groups.
Coverage timelineoldest first · each row is one article
- · 6d agoMultiple Chinese hacking groups seen using identical Chrome zero-day exploit
The Record· 85
Four China-linked espionage groups share identical BlueMoon Chrome zero-day exploit kit targeting US defense contractors and Asian government agencies.
- · 6d agoFour Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
The Hacker News· 82
Proofpoint links four espionage clusters, including China's APT31, using shared exploit kit BlueMoon chaining Chrome V8 and Windows ALPC zero-days.
- · 6d agoHackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks
Cyber Security News· 86
Multiple espionage actors, mostly China-nexus, are chaining Chrome V8 and Windows kernel zero-days (CVE-2026-85046, CVE-2026-85880) via the BlueMoon exploit kit against government and defense targets.
- · 6d ago4 groups caught using the same Chrome and Windows exploit kit
Ars Technica · Security· 85
Proofpoint says at least four groups, some China-linked, actively share the BlueMoon kit chaining two Chromium and one Windows kernel exploit.
- · 6d agoChinese espionage groups swarm to exploit triple-link chain of zero-days
Proofpoint Threat Insight· 85
Four China-aligned espionage groups, starting with TA412/APT31, chained zero-days CVE-2026-85046, CVE-2026-87491 and CVE-2026-85880 to spy on targets since late August.
- · 6d agoChinese espionage groups swarm to exploit triple-link chain of zero-days
CyberScoop· 88
At least four China-aligned espionage groups chained three zero-days in Chromium browsers and Windows ALPC for espionage since late August.
- · 6d agoFour groups caught using the same Chrome and Windows exploit kit
Proofpoint Threat Insight· 80
Proofpoint reports at least four hacking groups, some China-linked, share the BlueMoon exploit kit chaining Chromium and Windows kernel vulnerabilities to install malware.
- · 5d agoNovel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
The Register · Security· 85
Proofpoint reports the BlueMoon exploit kit, chaining two Chrome V8 zero-days and a Windows ALPC bug, being shared across China-linked espionage groups.
- · 5d agoChina-Linked Hackers Exploit Chrome and Windows Zero-Days in BlueMoon Attacks
GBHackers· 80
China-linked clusters deploy the BlueMoon kit chaining Chrome V8 CVE-2026-85046 and Windows LPE CVE-2026-85880 in espionage campaigns.
- · 5d agoFour Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Security Affairs· 85
Proofpoint reports four nation-state actors, mostly China-nexus, adopted the BlueMoon Chrome and Windows zero-day exploit kit within 12 days, targeting US organizations.
- · 5d agoNew 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
BleepingComputer· 85
Multiple China-linked espionage groups share the BlueMoon exploit kit chaining Chrome V8 zero-days and a Windows ALPC LPE to deploy backdoors.
- · 5d agoBlueMoon exploit kit turns Chrome and Windows flaws into attacks
Malwarebytes Labs· 75
Proofpoint documents BlueMoon exploit kit used by four espionage groups to chain Chrome V8 and Windows flaws via phishing, all now in CISA's KEV.
- · 5d agoSeptember Windows Server updates break Remote Desktop Services
BleepingComputer· 52
September 2026 Windows Server cumulative updates cause Remote Desktop Services failures on Server 2019, 2022 and 2025, forcing some admins to roll back.
- · 4d agoAttackers are weaponizing the gap between Chromium fixes and Chrome patches
CSO Online· 82
Espionage actors use the BlueMoon exploit kit to chain Chrome V8 and Windows kernel zero-days via spear phishing, gaining full admin on unpatched endpoints.
- · 4d agoRemote Desktop Services Failures on Windows Servers Following September Update
Cyber Security News· 55
September 2026 Patch Tuesday updates cause Windows Server 2019/2022/2025 RDS sessions to freeze, forcing administrators to roll back.
- · 4d agoWindows 11 Security Update KB5124008 Breaks Always-On VPN Connections
Cyber Security News· 48
Microsoft's September 2026 Windows 11 update KB5124008 breaks certificate-based Always On VPN on some enterprise clients, forcing admins to pause rollout.
- · 3d agoChina-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
GBHackers· 85
Volexity reports China-linked UTA0560 and JungleBamboo chained Chrome zero-day CVE-2026-85046 with kernel flaws to spy on NGOs.
- · 3d agoBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
SecurityWeek· 88
Proofpoint reports multiple espionage groups rapidly adopting BlueMoon, a new exploit kit chaining Chrome and Windows zero-days.
- · 16h agoChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
The Hacker News· 85
Volexity attributes spear-phishing campaign exploiting Chrome-Windows zero-day chain to Chinese actors UTA0560 and APT31 deploying GRIMWEDGE and LONGTALE.
- · 11h agoOne Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Security Affairs· 85
Two China-linked APT groups reused identical Chrome/Windows zero-day chain against NGOs, deploying GRIMWIDGE backdoor and LONGTALE credential-stealing extension.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85046 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2026-85046) Google Chrome versions prior to 152.0.7977.82 contain a type confusion flaw (CWE-843) in the V8 JavaScript engine, which mishandles object types during engine operations (public proof-of-concept writeups indicate it is reachable through array sorting and WebAssembly-related code paths). A remote attacker triggers the flaw simply by getting a user to open a crafted HTML page, with no privileges or authentication required. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, and public reporting shows it being chained with Windows zero-days (the 'BlueMoon' exploit kit) by Chinese espionage groups for broader compromise. Any user of an unpatched Chrome or another build embedding the affected V8 engine is exposed. The vulnerability is a zero-day that was actively exploited in the wild before patching, was added to CISA's KEV on 2026-09-04, and has five public proof-of-concept references. Do: Update Google Chrome to 152.0.7977.82 or later immediately, and apply the corresponding V8 fix in any Chromium-based browser in use. Federal agencies must apply mitigations in line with CISA BOD 26-04 and its cloud-services requirements, evaluating each asset's internet exposure. Because public reporting shows this flaw chained with Windows zero-days in 'BlueMoon' attacks, patch the related Windows vulnerabilities as well and hunt for signs of exploit-chain activity on high-exposure endpoints. | 8.8 | 1% | KEV PoC ×5 |
| massmultiple billions of users/installs (Chrome is the dominant desktop browser at roughly 65% market share, with an estimated 3+ billion active users, plus… | |
| CVE-2026-85880 | Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain. Do: Apply Microsoft's September 2026 security (cumulative) updates for each affected Windows 10 and Windows Server build, as no public PoC or workaround is documented; CISA's KEV listing (added 2026-09-08) triggers BOD 26-04 patching requirements for federal agencies, so prioritize accordingly. Give priority to hosts where unprivileged users can log in — RDS/VDI servers, jump boxes, shared workstations — and to internet-exposed Windows servers, since an ALPC local privilege escalation is a common component in exploit chains combining remote code execution or browser flaws with elevation to SYSTEM. Organizations unable to patch promptly should follow BOD 26-04 guidance for cloud services or restrict local access to affected hosts until updates are applied. | 7.8 | <1% | KEV |
| mass≈100M+ Windows installations (Windows 10 1607–22H2 on consumer/enterprise endpoints plus widely deployed Windows Server 2012–2022) | |
| CVE-2026-87491 | Actively Exploited Out-of-Bounds Write in Google Chrome V8 CVE-2026-87491 is an out-of-bounds write (CWE-787) in the V8 JavaScript engine in Google Chrome, fixed in Chrome 153.0.8010.36, which Google shipped alongside roughly 230 other security fixes. An attacker can trigger the flaw remotely by luring a user (user interaction required) into opening a crafted HTML page that corrupts memory in V8. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome browser sandbox, which constrains but does not eliminate the impact. All Google Chrome users running versions prior to 153.0.8010.36 are affected; because the flaw resides in V8, CISA tracks it as 'Google Chromium V8', and other Chromium-based browsers may inherit the fix in their own updates. The flaw is being actively exploited in the wild — it is the seventh actively exploited Chrome zero-day of 2026 and was added to CISA's KEV catalog on 2026-09-09 — though no public proof-of-concept is known and ransomware use is unknown. Do: Update Google Chrome to 153.0.8010.36 or later immediately (open Help > About Google Chrome to force the update and relaunch), and verify the version on all endpoints. Also patch headless or automated Chrome deployments (CI runners, scrapers, kiosks, CDP-based tooling) that may lag auto-updates, and prioritize remediation per CISA KEV and BOD 26-04 requirements for federal systems. No public PoC is known and ransomware use is unknown, but confirmed in-the-wild exploitation warrants urgent patching. | 8.8 | <1% | KEV |
| massbillions of installations (Chrome's install base exceeds 3 billion users) |