HackMyIP
← Back to News
2026-09-09 The Hacker News

BlueMoon Exploit Kit: Four Spy Groups Target Chrome and Windows in Days

Zero-DayAPTVulnerability

Multiple state-sponsored espionage clusters, most with suspected China ties, rapidly weaponized a previously undocumented exploit kit dubbed BlueMoon within days of each other, according to Proofpoint researchers. The first in-the-wild deployment was attributed to APT31 (also known as Bronze Vinewood, Judgement Panda, or Violet Typhoon) on August 28, 2026, after which at least three additional espionage-motivated activity clusters began leveraging the same toolset. While BlueMoon appears to be predominantly used by China-aligned actors, Proofpoint noted that some deployments remain unattributed and the kit may eventually spread to other threat groups.

BlueMoon chains together three vulnerabilities to achieve full code execution on targeted Windows machines. The attack begins with two V8 engine flaws in Google Chrome—CVE-2026-85046 (a type confusion bug) and CVE-2026-87491 (an out-of-bounds read enabling sandbox escape)—followed by CVE-2026-85880, a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem used for local privilege escalation. Both Chrome vulnerabilities were so-called "patch-gap" zero-days: the underlying bugs had already been fixed in upstream Chromium source code but had not yet propagated to stable browser releases. Security teams can assess their exposure by verifying browser versions and reviewing endpoint telemetry, and administrators should run a thorough privacy checkup on managed devices to confirm no suspicious browser extensions or profiles remain.

The attack chain is initiated through phishing emails that lure targets to actor-controlled URLs triggering the two V8 flaws in succession. Once code execution is achieved, the kit uses a reflectively loaded DLL to fingerprint the Windows host before deciding whether to attempt the LPE exploit; a second DLL then elevates the renderer process, allowing an injector shellcode to deliver cluster-specific payloads. Google's Chrome team patched both V8 flaws (including assigning a CVE for the sandbox escape despite not routinely doing so for such bugs), while Microsoft addressed the ALPC vulnerability as part of its September 2026 Patch Tuesday. Given the phishing-based delivery model, defenders should harden email gateways and verify suspicious links using an SSL/TLS checker before any user interaction, while users can confirm whether their credentials have appeared in known leaks via the email breach checker.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →