BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

A New Exploit Kit Emerges: BlueMoon Takes Advantage of Unpatched Chrome and Windows Vulnerabilities

Cybersecurity firm Proofpoint has discovered a new exploit kit dubbed BlueMoon, which is being used by multiple espionage groups to target various organizations worldwide. The exploit kit chains together three previously unpatched vulnerabilities in Chrome and Windows, demonstrating the ease with which threat actors can now create and deploy sophisticated malware.

The use of BlueMoon was first detected on August 28, when China-linked APT Violet Typhoon (also known as APT31) employed it in attacks targeting non-governmental organizations (NGOs), mining entities, and physical commodity trading firms in the US. Within days, other Chinese threat actors started using the exploit kit, suggesting that its rapid adoption may not be limited to groups affiliated with China.

According to Proofpoint, BlueMoon exploits two zero-day vulnerabilities in Chrome’s V8 JavaScript and WebAssembly engine (CVE-2026-85046 and CVE-2026-87491) to achieve a sandbox escape. It then uses a Windows Advanced Local Procedure Call (ALPC) privilege escalation vulnerability (CVE-2026-85880) to gain elevated privileges on the compromised system.

The exploit kit’s creators appear to have used artificial intelligence (AI) in its development, as evidenced by retrieved development artifacts that suggest AI-powered tooling was employed. However, this is not conclusive proof of AI involvement.

BlueMoon’s ease of adoption and deployment raises concerns about the proliferation of sophisticated malware. The fact that multiple threat actors obtained access to the exploit kit within a short period suggests a reduced barrier to entry for those seeking to create and deploy complex attacks.

The use of BlueMoon has been observed in various sectors, including government, consulting, finance, and manufacturing. UNK_LateNight, another China-linked espionage group, used it against US aerospace companies on September 2, while threat actors tracked as UNK_DoubleCheck targeted a manufacturing organization in Vietnam the following day.

The implications of this discovery are significant, highlighting the need for organizations to prioritize patching and remain vigilant against emerging threats. As Proofpoint notes, “BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals.”

To mitigate the risks associated with BlueMoon, it is essential for users to ensure they are running the latest versions of Chrome and Windows, as well as keeping their security software up-to-date. Regular monitoring of network activity and implementing robust incident response plans can also help organizations detect and respond to potential threats more effectively.

In conclusion, the emergence of BlueMoon serves as a stark reminder of the evolving threat landscape and the need for continued innovation in cybersecurity measures. As AI-powered tooling becomes increasingly accessible, it is crucial that organizations prioritize their defenses and stay informed about emerging threats to protect themselves against sophisticated attacks like those facilitated by BlueMoon.


Source: SecurityWeek — 2026-09-12