LmCast :: Stay tuned in

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Recorded: Sept. 10, 2026, 3:10 p.m.

Original Summarized

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

IDScan confirms breach tied to 153 million stolen driver’s licenses

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Microsoft says September updates fix mouse settings reset issues

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityNew 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

By Bill Toulas

September 10, 2026
10:11 AM
0

Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
BlueMoon combines two security issues in Chromium-based browsers that allow remote code execution and sandbox escape with a kernel local privilege escalation in Windows.
The kit appears to be a shared modular tool that supports exploit additions and was used in distinct operations.
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used since August 28 in spearphishing operations attributed to the JungleBamboo (a.k.a. APT31, Violet Typhoon, APT31, Tide Castle) threat actor associated with China.
Cybersecurity and threat intelligence company Volexity also observed similar activity on September 1st, in campaigns from another actor it tracks as UTA0560 that targeted "customers at multiple non-governmental organizations (NGOs)."
According to the researchers, the BlueMoon developer maintainers take advantage of the delay between public Chromium fixes and stable Chrome releases, reverse-engineer public code changes, and create exploits to target downstream browser users.
The three flaws chained by the BlueMoon exploit kit are:
CVE-2026-85046: a type-confusion flaw in Chrome’s V8 JavaScript engine that provides arbitrary memory access inside the V8 sandbox
CVE-2026-87491: a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode
CVE-2026-85880: a heap-based buffer overflow in Windows ALPC that allows local privilege escalation
Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it has been leveraged since 2025 and repackaged in BlueMoon.
“The LPE DLL compilation timestamp is from 2025 and did not appear to be forged,” Proofpoint explains.
“This - combined with the exploit targeting older Windows builds - suggests that the exploit creator repackaged an existing capability into the BlueMoon exploit kit.”
BlueMoon runs the exploit inside a Web Worker, retrying it up to five times. It fingerprints the system, exploits the Windows privilege elevation flaw to elevate the Chrome renderer, and injects into Chrome’s parent process to run an operator-selected command.
The default final command uses curl to save an executable, typically a malware loader, under %TEMP% and run it.

BlueMoon attack chain overviewSource: Proofpoint
Threat groups and targets
The reports from Volexity and Proofpoint [1, 2] identify four distinct activity clusters associated with BlueMoon deployments, three of them described as Chinese or China-aligned.
JungleBamboo, the first Chinese state-sponsored actor observed using BlueMoon, is known for targeting NGOs in the US, mining companies, and individual high-value targets, using the Longtale/GemStone credential stealer extension disguised as Google Gemini.
The second hacker group is UTA0560, which targeted NGOs using donation lures and triggered an infection chain that delivered Grimwedge, an in-memory JScript backdoor for reconnaissance, file and process management, command execution, and payload uploads.

Phishing emails used in the attacksSource: Proofpoint
The third cluster is tracked as UNK_LateNight, known for deploying the ShadowPad backdoor on systems belonging to U.S. aerospace and defense-industrial-base companies.
A fourth group, tracked as UNK_DoubleCheck, targeted Vietnamese manufacturing firms with an in-memory Rust loader, though the final payload couldn’t be retrieved for analysis.
Proofpoint expects BlueMoon adoption and deployment to increase, potentially reaching financially motivated attackers in the future, so defenders are advised to use the provided indicators of compromise in both reports to block the activity early.
Both cybersecurity companies shared indicators of compromise for files and network infrastructure observed in attacks using the BlueMoon exploit kit.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
Google warns of new Chrome zero-day bug exploited in attacksMagento StyleSmuggler zero-day exploited to deploy Linux backdoorN-able patches max severity N-central flaw amid ongoing attacksSonicWall warns of actively exploited SMA1000 zero-day flawsSonicwall warns of new SMA1000 zero-day exploited in attacks

Actively Exploited
APT31
BlueMoon
Exploit Kit
UNK_DoubleCheck
UNK_LateNight
UTA0560
Zero-Day

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

Overdue a password health-check? Audit your Active Directory for free

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Multiple cyber-espionage groups utilize an exploit kit named BlueMoon, which leverages zero-day vulnerabilities in Microsoft Windows and Google Chrome to achieve system compromise. This exploit kit is characterized as a shared, modular tool that successfully chains together security issues in Chromium-based browsers with a local privilege escalation flaw in Windows. Researchers at Proofpoint and Volexity observed the deployment of BlueMoon in spearphishing operations attributed to actors such as JungleBamboo, associated with China, and UTA0560, which targeted non-governmental organizations.

The methodology employed by the developers of BlueMoon involves exploiting the time delay between public browser security fixes and stable releases to reverse-engineer public code changes, enabling them to craft exploits targeting end-users. The exploit chain relies on three specific vulnerabilities: CVE-2026-85046, a type-confusion flaw within Chrome’s V8 JavaScript engine that permits arbitrary memory access inside the V8 sandbox; CVE-2026-87491, a sandbox escape vulnerability that corrupts WebAssembly metadata to allow the execution of embedded shellcode; and CVE-2026-85880, a heap-based buffer overflow in the Windows ALPC that facilitates local privilege escalation. Proofpoint noted that the local privilege escalation vulnerability was suspected to have been leveraged since 2025 and repackaged within the BlueMoon kit.

The operation of the BlueMoon exploit kit involves executing the exploit within a Web Worker, which fingerprints the system before exploiting the Windows privilege elevation flaw to escalate privileges to the Chrome renderer. From there, the exploit injects commands into Chrome’s parent process, allowing the attacker to execute a command selected by the operator. The default command utilized by the kit typically involves using curl to save an executable, usually a malware loader, into the temporary directory and subsequently running it.

The observations from cybersecurity firms identified four distinct activity clusters associated with the BlueMoon deployments. The first cluster involved JungleBamboo, a state-sponsored actor known for targeting NGOs, mining companies, and high-value targets using credential stealers. The second cluster tracked by Volexity involved the UTA0560 group, which used donation lures to infect NGOs and deploy Grimwedge, an in-memory JScript backdoor for reconnaissance, file and process management, command execution, and payload uploads. The third cluster was tracked as UNK_LateNight, which deployed the ShadowPad backdoor on systems belonging to U.S. aerospace and defense-industrial-base companies. Finally, the fourth group, UNK_DoubleCheck, targeted Vietnamese manufacturing firms by deploying an in-memory Rust loader, although the final payload remains unanalyzed. Defenders are advised to utilize the indicators of compromise shared by these cybersecurity companies to proactively block the activity related to the BlueMoon exploit kit. Furthermore, the report contextualizes defensive posture by noting that once attackers possess valid credentials, prevention efficacy drops significantly, as only thirty-seven percent of their subsequent actions are blocked.