BlueMoon Exploit Kit: Chrome & Windows Zero-Days Chained by APTs
Proofpoint researchers have identified a new exploit kit dubbed BlueMoon that chains three previously unpatched vulnerabilities—two zero-days in Chrome and one in Windows—to compromise targeted systems. First deployed on August 28 by China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle), the kit spread rapidly to multiple distinct threat actors within days, suggesting unusually fast distribution among espionage groups. "It is currently unknown how multiple distinct threat actors obtained access to the exploit kit," Proofpoint noted, warning that the kit is "likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors."
The exploit chain leverages CVE-2026-85046 and CVE-2026-87491, both V8 JavaScript and WebAssembly engine flaws in Chrome that were patched as zero-days on September 3 and September 8, respectively. BlueMoon uses these defects to escape the Chrome sandbox, then fingerprints the host and triggers CVE-2026-85880, a privilege escalation vulnerability in Windows Advanced Local Procedure Call (ALPC) that was addressed during the September 2026 Patch Tuesday. After gaining elevated privileges, a CreateProcess stub is injected into the parent Chrome broker process to download and execute payloads via a curl command. Despite multiple packaging variations identified by Proofpoint, all BlueMoon samples share identical orchestration and loading mechanisms.
Initial attacks by Violet Typhoon focused on US-based NGOs, mining entities, and physical commodity trading firms. Starting September 2, second China-linked group UNK_LateNight began exploiting US aerospace companies, while UNK_DoubleCheck targeted a manufacturing organization in Vietnam. A day later, UNK_QuietRacket deployed BlueMoon against government, consulting, and financial entities in Indonesia and Singapore. Researchers also recovered development artifacts suggesting possible AI-assisted construction, "though no single artifact conclusively confirms this," according to Proofpoint.
The kit's rapid proliferation—deployed and shared among multiple actors within days while generating high detection signals—may reflect a reduced barrier to entry for advanced exploit development as AI agents increasingly enable threat actor capabilities. Organizations and individuals concerned about browser-based threats can run a browser fingerprint test to assess their exposure profile, or use the privacy checkup to identify vulnerable browser configurations that could heighten risk during targeted campaigns. Ensuring Chrome is updated to the latest build and Windows patches are applied remains the most effective defense against this exploit chain.