Multiple espionage groups have begun using a new exploit kit called BlueMoon in what appear to be opportunistic, fast-moving campaigns, according to research from Proofpoint. The kit chains together three vulnerabilities that were unpatched at the time of its first known use.
The China-linked group Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first observed user, deploying BlueMoon on August 28. Within days, several other Chinese threat actors adopted the same toolkit, and Proofpoint says the activity may not remain limited to China-aligned groups.
The Exploit Chain
BlueMoon combines two Chrome zero-days, tracked as CVE-2026-85046 and CVE-2026-87491, both affecting the V8 JavaScript and WebAssembly engine, with a Windows privilege escalation flaw in Advanced Local Procedure Call (ALPC), tracked as CVE-2026-85880. The Chrome bugs were patched on September 3 and September 8 respectively, and the Windows flaw was fixed as part of the September 2026 Patch Tuesday.
According to Proofpoint, the kit exploits the V8 defects to escape the browser sandbox, fingerprints the compromised host, and then executes privilege escalation code. A CreateProcess stub is injected into the parent Chrome broker process, which downloads and runs an executable via a curl command.
Rapid Cross-Group Adoption
Proofpoint identified several packaging variants of BlueMoon, all sharing the same underlying exploit chain and identical orchestration and loading logic. Retrieved development artifacts suggest the kit’s creators may have used AI tools during development, though the firm says no single artifact conclusively proves this.
Violet Typhoon initially used BlueMoon against US-based NGOs, mining companies, and physical commodity trading firms. Starting September 2, a separate China-linked group tracked as UNK_LateNight used it against US aerospace companies, while UNK_DoubleCheck targeted a manufacturing organization in Vietnam. The following day, UNK_QuietRacket used the kit against government, consulting, and financial targets in Indonesia and Singapore.
Proofpoint notes that BlueMoon was developed, deployed, and shared across multiple actors within days despite generating high detection signals, which it says may reflect a lower barrier to entry for building this class of exploit chain as AI agents increasingly assist in exploit development.
Organizations should ensure the September 2026 Chrome and Windows patches addressing these three vulnerabilities have been applied, given the kit’s demonstrated speed of adoption across distinct threat actor groups.
