Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Broken Clouds Humidity: 90%
Wind: 3.09 M/S

Cybercriminals Combine Chrome and Windows Zero-Days in Sophisticated BlueMoon Campaign

Cybercriminals Combine Chrome and Windows Zero-Days in Sophisticated BlueMoon Campaign

Several espionage-focused threat actors have begun leveraging a newly discovered exploit framework known as BlueMoon, combining vulnerabilities in Google Chrome and Microsoft Windows to deploy surveillance tools and backdoors against government, defense, and commercial organizations worldwide.

Researchers at Proofpoint identified the exploit kit being used by at least four separate threat clusters since late August 2026. Most of the observed activity appears to be linked to China-based cyberespionage operations, highlighting the rapid adoption of sophisticated exploit capabilities among nation-state aligned actors.

The earliest confirmed activity was attributed to TA412, also known as Violet Typhoon (APT31), which deployed the exploit chain on August 28, 2026. Within days, multiple additional threat groups had incorporated the same toolkit into their campaigns.

How the BlueMoon Exploit Chain Works

The BlueMoon framework combines three vulnerabilities to achieve full system compromise.

The attack begins with CVE-2026-85046, a type-confusion flaw in Chromium's V8 JavaScript engine. By exploiting an optimization weakness in the Just-In-Time (JIT) compiler, attackers can execute arbitrary code within the browser renderer process.

The second stage escapes Chrome's security sandbox by manipulating WebAssembly metadata, allowing attackers to overwrite compiled functions with malicious shellcode.

The final phase targets CVE-2026-85880, a privilege escalation vulnerability in the Windows kernel. By abusing Advanced Local Procedure Calls (ALPC) and the Windows Notification Facility (WNF), attackers gain kernel-level read and write capabilities, ultimately elevating privileges and taking control of the compromised system.

A notable aspect of BlueMoon is that the browser vulnerabilities were "patch-gap" zero-days. Although fixes had already been committed to Chromium's public codebase, they had not yet reached stable browser releases. This created a window of approximately four weeks during which attackers could reverse-engineer and weaponize the vulnerabilities before most users received updates.

Signs of Rapid Development

According to researchers, several characteristics suggest BlueMoon was deployed quickly rather than developed as part of a long-term, highly refined operation.

The Windows privilege escalation component only functions reliably on older platforms, including Windows 10 and Windows Server 2019 and 2022, limiting the number of viable targets. Researchers also observed that domains and infrastructure used in many campaigns were registered shortly before launch, indicating fast-moving operations.

Unlike many advanced exploit chains that prioritize stealth, BlueMoon's default payload simply executes a curl command to download and run additional malware. While effective, this approach generates multiple opportunities for endpoint detection and security monitoring systems.

Researchers also uncovered indicators that portions of the toolkit may have been developed with the assistance of AI coding tools. Evidence included extensive debugging output, detailed diagnostic logging, and references to markdown-based handover documents commonly associated with AI-assisted software development workflows.

The exploit code also contains references to Google's v8CTF bug bounty environment. Researchers remain uncertain whether these references stem from legitimate vulnerability research or represent attempts to bypass safeguards in AI-assisted development tools.

Diverse Campaigns, Shared Capabilities

The exploit kit has already appeared across multiple espionage campaigns targeting different sectors and regions.

TA412 employed spear-phishing emails disguised as university internship opportunities and academic conference invitations to target U.S. nongovernmental organizations, mining firms, and commodity trading companies. Successful compromises resulted in the deployment of a malicious browser extension masquerading as Google Gemini, which researchers track as GemStone.

GemStone functions as a full-featured browser surveillance platform capable of:

  • Capturing keystrokes
  • Stealing cookies and session data
  • Taking screenshots
  • Executing arbitrary web requests
  • Communicating with remote command-and-control infrastructure

Another cluster, dubbed UNK_LateNight, targeted U.S. aerospace and defense organizations using procurement-themed lures. Victims ultimately received the ShadowPad backdoor through a DLL sideloading infection chain.

Researchers also observed UNK_DoubleCheck compromising a government email account in Southeast Asia to target a Vietnamese manufacturer with a Rust-based malware loader.

Meanwhile, UNK_QuietRacket focused on government and financial institutions in Indonesia and Singapore, using conference-themed phishing campaigns and DNS-over-HTTPS communication channels to conceal command-and-control traffic.

Lowering the Barrier to Exploit Development

Proofpoint's findings suggest that the historical barriers associated with developing sophisticated browser exploit chains may be shrinking.

Previously, creating reliable browser and kernel exploit chains required significant expertise, resources, and investment. However, advances in AI-assisted development tools appear to be accelerating vulnerability research and exploit creation, particularly against open-source projects such as Chromium.

The speed at which multiple threat actors gained access to BlueMoon also raises questions about a shared distribution or procurement ecosystem. Researchers noted similarities to previous mass exploitation events involving Microsoft Exchange and SharePoint vulnerabilities, where exploit capabilities spread rapidly across numerous threat groups.

Security Implications

Organizations running older Windows versions alongside unpatched Chromium-based browsers face the greatest risk from BlueMoon-related activity.

Researchers expect patch-gap exploitation techniques to become increasingly common as attackers look to capitalize on the period between source-code fixes and widespread patch deployment. As both nation-state and financially motivated actors continue adopting these methods, organizations will need to prioritize rapid browser updates, operating system patching, and proactive monitoring to reduce exposure to similar exploit chains in the future.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.