Skip to content
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors

BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors

First seen 9 Sep 2026, 17:14 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 10, 2026 at 16:02 UTC

A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by other groups within days. The exploit kit chains three vulnerabilities: CVE-2026-85046, a type confusion flaw in Chrome's V8 JavaScript engine, a V8 sandbox escape, and CVE-2026-85880, a Windows local privilege escalation vulnerability. The exploit takes advantage of a four-week patch gap, allowing attackers to reverse-engineer fixes before they are applied to stable releases. The targeted sectors include U.S. defense contractors, NGOs, and Southeast Asian government agencies. Microsoft and Google have since released patches for the vulnerabilities. The situation remains dynamic, with ongoing investigations into the extent of the exploitation and the actors involved.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2019-02-18
Public exploit for CVE-2025-5419 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2023-09-12
CVE-2023-4863 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-09-28
CVE-2023-5217 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-11-29
CVE-2023-6345 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-12-21
CVE-2023-7024 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-16
CVE-2024-0519 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-02-13
CVE-2024-21338 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-03-26
CVE-2024-2883 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-05-09
CVE-2024-4671 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-05-14
CVE-2024-4761 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (17)

Following this threat?

Track APT31, AppleJeus and CVE-2023-4863 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed