Therecord.Media BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors
Article Content
- •BlueMoon exploit kit used by at least four state-aligned threat actors.
- •Exploits vulnerabilities in Chrome and Windows, including CVE-2026-85046 and CVE-2026-85880.
- •Rapid adoption of the exploit kit highlights a concerning trend in cyber espionage.
A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by other groups within days. The exploit kit chains three vulnerabilities: CVE-2026-85046, a type confusion flaw in Chrome's V8 JavaScript engine, a V8 sandbox escape, and CVE-2026-85880, a Windows local privilege escalation vulnerability. The exploit takes advantage of a four-week patch gap, allowing attackers to reverse-engineer fixes before they are applied to stable releases. The targeted sectors include U.S. defense contractors, NGOs, and Southeast Asian government agencies. Microsoft and Google have since released patches for the vulnerabilities. The situation remains dynamic, with ongoing investigations into the extent of the exploitation and the actors involved.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track APT31, AppleJeus and CVE-2023-4863 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Armored Likho Expands Cyber-Espionage with New Rust Toolkit In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and educational institutions. The attackers employed a fraudulent donation-service application as the initial…
Spearphishing Campaigns Exploit Malicious Links for User Execution Recent reports detail various adversaries utilizing spearphishing tactics to exploit users into clicking malicious links. These links often lead to the execution of malware or the harvesting of sensitive information, including credentials. Notable threat actors such as APT28, APT29, and FIN7 have been identified as…