BlueMoon Exploit Kit Spreads to Four Spy Groups in Six Days
Security / news
BlueMoon Exploit Kit Spreads to Four Spy Groups in Six Days
Proofpoint says it still cannot explain how rival state-aligned hacking teams ended up sharing the same three-flaw chain within a week of its first use.

An exploit kit chaining a Chrome sandbox escape to a Windows privilege-escalation bug reached four separate espionage-motivated hacking teams within six days of its first confirmed use, Proofpoint said in a Sept. 9 report. The firm's researchers named it BlueMoon.
Proofpoint said the group it tracks as TA412, also known as Violet Typhoon, JungleBamboo and APT31, used BlueMoon first, on Aug. 28, 2026, against U.S. non-profits, mining firms and commodity traders. Three more clusters were using the same chain by Sept. 3.
The three flaws BlueMoon chains together
BlueMoon strings together two Chrome bugs and one Windows bug, according to Proofpoint and a Sept. 12 writeup from SecurityWeek. CVE-2026-85046 is a type-confusion flaw in Chrome's V8 engine, letting a crafted web page run code inside the browser's sandbox; Google fixed it in Chrome 152.0.7977.82. CVE-2026-87491 overwrites WebAssembly function bodies to escape that sandbox. Jihyeon Jeong, a research intern at Seoul National University's Compsec Lab, reported that flaw to Google, which shipped a fix two days later, on Sept. 9, in Chrome 153.0.8010.36 for Windows and Linux and 153.0.8010.37 for Mac. The last link, CVE-2026-85880, is a heap-based buffer overflow in the Windows Advanced Local Procedure Call component, rated 7.8 on the CVSS scale, that hands the resulting process SYSTEM-level privileges once it is already running outside the browser sandbox.
The rating undersells the chain rather than the flaw. On its own, a local privilege escalation bug with a 7.8 score is unremarkable. Bolted to a remote browser exploit that needs only a visit to a malicious page, it becomes the step that turns a sandboxed renderer compromise into full control of the machine.
Four groups, six days, four target lists
Each of the four clusters Proofpoint identified pointed BlueMoon at a different set of victims, which is what convinced the firm the kit is shared rather than reused by one actor under different names.
| Threat actor | First seen using BlueMoon | Primary targets |
|---|---|---|
| TA412 (Violet Typhoon / APT31) | Aug. 28, 2026 | U.S. non-profits, mining, commodity trading |
| UNK_LateNight | Sept. 2, 2026 | U.S. aerospace and defense industrial base |
| UNK_DoubleCheck | Sept. 2, 2026 | Vietnamese manufacturing |
| UNK_QuietRacket | Sept. 3, 2026 | Indonesian and Singaporean government, finance, consulting |
Washington's deadline for the Windows half has already passed
CISA added CVE-2026-85880 to its Known Exploited Vulnerabilities catalog on Sept. 8, 2026, setting Sept. 22 as the deadline for U.S. federal civilian agencies to patch it under Binding Operational Directive 26-04. That date has come and gone; the same catalog entry carries no note that the deadline was met. Microsoft shipped the Windows fix as part of its Sept. 8 Patch Tuesday release. Chrome's two flaws were closed earlier, on Sept. 3 and Sept. 8 respectively, through Google's normal auto-update channel, which does not depend on an administrator applying anything.
This site previously covered a double-fetch bug reaching SYSTEM in Avast's own sandbox, a reminder that a local Windows privilege step, not the flashier remote entry point, is often what a full compromise chain actually needs. CISA has also pushed short remediation windows for less severe bugs this month, including a 9.8-rated flaw in lwIP's MQTT client.
What Proofpoint still will not guess at
Proofpoint's report is explicit about the gap in its own findings. "It is currently unknown how multiple distinct threat actors obtained access to the exploit kit," the company said, adding that BlueMoon's apparent ease of adoption means it is likely to keep spreading. The firm did not attribute the kit's original authorship to any of the four clusters using it, and neither Google nor Microsoft has commented publicly on how a chain combining their products passed between unrelated state-aligned groups so quickly.
For anyone running Windows builds still receiving support from the affected list, patching CVE-2026-85880 closes the local half of the chain; keeping Chrome on its auto-update channel past version 153.0.8010.36 closes the other two links. Older, unsupported Windows versions on the CISA list have no fix coming.
Sources
More in Security
- 01CISA Gives Agencies 3 Days to Patch an Exploited SharePoint BugMicrosoft rated the flaw a low-risk spoofing issue for 16 days after patching it, and a honeypot logged the first attack four weeks after the correction upgraded it to an 8.8.
- 02CISA Adds a Fourth MikroTrick Bug to Its Exploited ListCVE-2026-67279 joins two other bugs from the same six-flaw MikroTik batch already on CISA's list, but Bishop Fox says it, not the pair flagged in September, is the one that actually opens the door.
- 03OpenClaw's New Scanners Agree on Just 0.69% of Risky SkillsFour audits since February have counted between 341 and 1,467 malicious or flawed skills on ClawHub, and NVIDIA's scanner disagrees with the other two on all but 468 of 67,453 skills checked.
- 04CISA Lists 14 Botslab Dashcam Flaws With No Fix in SightThe worst of the bugs lets a network attacker push firmware with no cryptographic signature onto the device, and Botslab has not told CISA whether it plans to fix any of the 14.