Therecord.Media
BlueMoon Exploit Kit Targeting Chrome and Windows Vulnerabilities
Article Content
A new exploit kit named BlueMoon has been rapidly adopted by multiple espionage-motivated threat actors, primarily linked to Chinese state intelligence. The first observed use was by the China-aligned group APT31 on August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046, a type confusion in Chrome's V8 engine, a V8 sandbox escape without a CVE, and CVE-2026-85880, a Windows local privilege escalation vulnerability. The exploit chain targets users through spear-phishing emails, leading to code execution and system compromise. The vulnerabilities were in a 'patch-gap' state, meaning they were known but not yet patched in stable Chrome releases. As of now, multiple threat actors are utilizing this exploit kit, raising concerns about its proliferation. The situation is ongoing, with security researchers expecting further reports on the campaign.
Key Points: • BlueMoon exploit kit targets Chrome and Windows vulnerabilities. • At least four espionage groups, mainly linked to China, are using this kit. • The exploit chain leverages multiple zero-day vulnerabilities in a coordinated attack.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.