BlueMoon Exploit Kit Targeting Chrome and Windows Vulnerabilities

BlueMoon Exploit Kit Targeting Chrome and Windows Vulnerabilities

First seen 9 Sep 2026, 17:14 UTC ProofpointThehackernewsTherecord.MediaCybersecuritynewsnvd.nist.gov+1 80.8

Article Content

Browse articles
ThreatCluster

A new exploit kit named BlueMoon has been rapidly adopted by multiple espionage-motivated threat actors, primarily linked to Chinese state intelligence. The first observed use was by the China-aligned group APT31 on August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046, a type confusion in Chrome's V8 engine, a V8 sandbox escape without a CVE, and CVE-2026-85880, a Windows local privilege escalation vulnerability. The exploit chain targets users through spear-phishing emails, leading to code execution and system compromise. The vulnerabilities were in a 'patch-gap' state, meaning they were known but not yet patched in stable Chrome releases. As of now, multiple threat actors are utilizing this exploit kit, raising concerns about its proliferation. The situation is ongoing, with security researchers expecting further reports on the campaign.

Key Points: • BlueMoon exploit kit targets Chrome and Windows vulnerabilities. • At least four espionage groups, mainly linked to China, are using this kit. • The exploit chain leverages multiple zero-day vulnerabilities in a coordinated attack.

Ask AI about this cluster

Timeline

2026-08-28
APT31 first observed using BlueMoon
APT31 was the first group to deploy the BlueMoon exploit kit against various targets.
Proofpoint
2026-09-03
CVE-2026-85046 published
Google published a fix for a type confusion vulnerability in Chrome's V8 engine.
Thehackernews
2026-09-04
CVE-2026-85046 added to CISA KEV
CISA listed CVE-2026-85046 as actively exploited, highlighting its importance.
Thehackernews
2026-09-08
CVE-2026-85880 published and added to CISA KEV
Microsoft published a fix for a Windows local privilege escalation vulnerability, also listed by CISA.
Proofpoint