VMTech
Discuss a project

BlueMoon Kit Shared by Four Spy Groups Exploits Chrome and Windows

BlueMoon Kit Shared by Four Spy Groups Exploits Chrome and Windows

Four espionage-focused threat clusters used the previously undocumented BlueMoon exploit kit within a week, chaining vulnerabilities in Google Chrome and Microsoft Windows. Proofpoint attributed the first observed in-the-wild use to China-aligned APT31 on August 28, 2026, followed by three additional clusters from September 2 to September 3.

BlueMoon combines CVE-2026-85046, a type-confusion vulnerability in Chrome’s V8 engine, an unassigned V8 sandbox escape, and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call. Google patched CVE-2026-85046 the previous week, while Microsoft addressed CVE-2026-85880 in its September 2026 Patch Tuesday updates.

A patch-gap browser exploit chain

Proofpoint described both V8 issues as patch-gap zero-days: fixes were available in public upstream Chromium code but had not yet reached stable Chrome and Chromium-based browser releases. The researchers said the exploit-kit developer may have monitored public Chromium patches to assemble a working browser chain before downstream releases were updated.

Victims receive spear-phishing messages leading to actor-controlled URLs. The landing pages trigger the two V8 vulnerabilities to execute code and escape Chrome’s sandbox. BlueMoon then loads a DLL reflectively to fingerprint the Windows host, allowing its JavaScript to decide whether to attempt the local privilege-escalation exploit.

A second reflectively loaded DLL elevates the renderer process. Injector shellcode then places a CreateProcess stub into the parent Chrome broker process, executing an operator-selected command. By default, that command uses curl to download and run a remotely hosted executable.

Different payloads, shared core capability

APT31 targeted US NGOs, mining companies and physical commodity trading firms. Its campaign installed GemStone, a browser-surveillance and credential-theft extension disguised as Google Gemini, using the GhostChrome-X Chrome extension integrity-bypass technique.

UNK_LateNight targeted US aerospace companies and delivered ShadowPad through DLL sideloading. UNK_DoubleCheck targeted a Vietnamese manufacturing entity and used a Cloudflare Workers domain, a Rust binary and a Cloudflare R2 Bucket in a multi-stage sideloading sequence. UNK_QuietRacket targeted government, consulting and financial organizations in Indonesia and Singapore, ultimately using an in-memory .NET payload to create scheduled-task persistence.

The rapid use of the same chain reinforces the importance of browser patching, a concern also reflected in Chrome security fixes and active attack activity examining Chrome security fixes and active attack activity. Yet an update only closes the initial access path; it does not remove a malicious extension, downloaded malware or scheduled task already created on a host.

Detection and response priorities

CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on September 4 and set a September 18 deadline for US federal civilian agencies to patch. Proofpoint also released detection rules 2071919 through 2071924 for BlueMoon’s JavaScript loader and command-and-control traffic.

Teams that may have been targeted should investigate chrome.exe launching cmd.exe, then curl.exe and msgbox.exe; ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder; C:\Users\Public\stomp_ext; the listed scheduled tasks; the Dataupcheckinfo mutex; and the specified CLSID registry key. The practical business implication is to pair urgent Chromium patching with endpoint hunting and phishing review, because remediation must address both exploit exposure and any persistence left behind.

#cybersecurity#chromesecurity#threathunting#patchmanagement
Open analytics
On the site 0 views
min read 4 09.09.2026
Instagram

BlueMoon Kit Shared by Four Spy Groups Exploits Chrome and Windows

Open the post on Instagram ↗