[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fycpTbLfqPHVhVwU5xSYg-KquiR27MnkwrJgufopBVTQ":3},{"article":4,"iocs":58},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"0994a83f-fd18-40b2-a058-b5cb701e2838","BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days","bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days-5fcbcf","Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.","A new exploit kit named BlueMoon is being rapidly adopted by multiple espionage-motivated threat actors, including China-linked groups like Violet Typhoon. The kit chains together two unpatched Chrome zero-days and one Windows zero-day, enabling sandbox escape and privilege escalation. Its ease of adoption suggests a potential proliferation and use by both espionage and financially motivated actors, possibly with AI assistance in its development.","BlueMoon exploit kit chains Chrome and Windows zero-days, adopted by multiple espionage groups.","Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it on August 28. Within days, several other Chinese threat actors started using it, but the activity might not be exclusive to China-aligned groups. “It is currently unknown how multiple distinct threat actors obtained access to the exploit kit. Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors,” Proofpoint notes. The BlueMoon exploit kit was adopted fast because it chains together three vulnerabilities that were unpatched when it first emerged: two zero-days in Chrome and one in Windows. Tracked as CVE-2026-85046 and CVE-2026-87491, the Chrome flaws were patched as zero-days on September 3 and September 8, respectively. Both impact the V8 JavaScript and WebAssembly engine. The Windows zero-day, tracked as CVE-2026-85880, was fixed on September 2026 Patch Tuesday. It is a privilege escalation in Windows Advanced Local Procedure Call (ALPC).Advertisement. Scroll to continue reading. BlueMoon, Proofpoint says, exploits the V8 defects for sandbox escape, then fingerprints the host and executes the privilege escalation code. Next, a CreateProcess stub is injected into the parent Chrome broker process to download an executable via a curl command and execute it. Proofpoint identified several packaging variations of BlueMoon, all using the same underlying exploit chain and identical orchestration and loading mechanisms. Retrieved development artifacts suggest that the exploit kit’s creators might have used AI to build it, “though no single artifact conclusively confirms this,” Proofpoint says. BlueMoon was initially used by Violet Typhoon in attacks targeting NGOs in the US, as well as mining entities and physical commodity trading firms. Starting September 2, a second China-linked espionage group, tracked as UNK_LateNight, used it against multiple US aerospace companies, and a threat actor tracked as UNK_DoubleCheck targeted a manufacturing organization in Vietnam. The next day, Chinese espionage group UNK_QuietRacket started using it in attacks against government, consulting, and financial entities in Indonesia and Singapore. “BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development,” Proofpoint notes. Related: North Korean Hackers Deploy New Linux Espionage Toolkit Related: Modified ScreenConnect Clients Used in Worm-Like Campaign Related: AI Speeds Up Malware Development, Not Its Success Rate: Analysis Related: Rust Supply Chain Attack Linked to North Korean Hackers Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Surfshark Systems Targeted by HackersPaperCut Flaws Exploited in AI-Powered AttacksCritical NetScaler Vulnerability Exploited in Attacks4.1 Million Impacted by AdaptHealth Data BreachNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft DefenderFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksHelmGuard Raises $7.3 Million for Agentic GRC and SecurityAndroid’s September 2026 Updates Patch 180 Vulnerabilities Latest News Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic SaysPhishing Research Challenges Conventional Security Awareness TestingGitLab Vulnerability Exploited One Day After DisclosureIn Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings ReviewTrezor Says 347,000 Users Received Phishing Emails After Brevo HackUkrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonCheck Point Patches Critical VPN VulnerabilitiesKiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fbluemoon-exploit-kit-chains-recent-chrome-windows-zero-days\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F03\u002Fexploit.jpeg","2026-09-12T11:10:00+00:00","2026-09-12T12:00:23.234024+00:00",9,[18,21,23,25,27,29],{"name":19,"type":20},"Violet Typhoon","threat_actor",{"name":22,"type":20},"APT31",{"name":24,"type":20},"JungleBamboo",{"name":26,"type":20},"TA412",{"name":28,"type":20},"Tide Castle",{"name":30,"type":31},"Chrome","product","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":32,"icon":34,"name":35,"slug":36},null,"Threat Intelligence","threat-intelligence",[38,43,48,53],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":54},{"id":55,"icon":34,"name":56,"slug":57},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",[59,63,65],{"type":60,"value":61,"context":62},"cve","CVE-2026-85046","Chrome zero-day impacting V8 JavaScript and WebAssembly engine.",{"type":60,"value":64,"context":62},"CVE-2026-87491",{"type":60,"value":66,"context":67},"CVE-2026-85880","Windows zero-day, privilege escalation in ALPC."]