At least four espionage groups, most with suspected links to China, deployed a new exploit kit called BlueMoon that chains Chromium-based browser flaws with a Windows privilege escalation bug. The attacks exploited a patch gap window and may reflect AI-driven exploit development, marking a shift in how quickly sophisticated attack tools proliferate.

Four China-Aligned Groups Deploy Shared Exploit Kit

At least four hacking groups, most with suspected links to China, are actively using a nearly identical Chrome and Windows exploit kit called BlueMoon to break into organizations across the United States and Southeast Asia. Security firm Proofpoint

1

revealed on Wednesday that the BlueMoon exploit kit chains three vulnerabilities together, allowing attackers to install malware of their choice on compromised systems.

Source: The Register

Source: The Register

The four espionage groups deploying this kit include TA412, a China-aligned state-sponsored threat actor indicted by the US government in 2024 on behalf of China's civilian foreign intelligence agency. TA412, also known as Violet Typhoon and APT31, repeatedly targeted NGOs, mining companies, and commodity trading firms in the US. A second China-aligned espionage group, UNK_LateNight, focused on multiple US aerospace companies. UNK_DoubleCheck targeted a Vietnamese manufacturing entity, while UNK_QuietRacket activity focused on Singapore and Indonesia

2

. Mark Kelly, a threat researcher at Proofpoint, told The Register that fewer than 20 organizations globally were targeted across the highlighted activity, though the true number is almost certainly higher.

Exploiting Chromium-Based Browsers and Windows Systems

The BlueMoon exploit kit targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows. The attack chain exploits two vulnerabilities in V8, Google's open-source JavaScript engine, and one Windows privilege escalation bug. The first V8 vulnerability, tracked as CVE-2026-85046, is a type confusion flaw that allows remote code execution and affects all Chromium-based browsers, including Google Chrome and Microsoft Edge. The second is a Chrome V8 sandbox escape that also affected all Chromium-based browsers but does not have a CVE designation because Google doesn't assign them for sandbox escapes.

The third vulnerability, CVE-2026-85880, is a privilege escalation bug in Windows Advanced Local Procedure Call affecting Windows 10, Windows 22, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours. Google patched CVE-2026-85046 in Chrome on September 3, warning that "an exploit for CVE-2026-85046 exists in the wild." Microsoft published a security advisory fixing the flaw in Edge Stable version 152.0.4191.62 on September 2, and patched the Windows bug CVE-2026-85880 on Tuesday, also warning it had been exploited as a zero-day prior to the security update.

Patch Gap Window Enables Rapid Weaponization

Both V8 vulnerabilities exploited by BlueMoon were "patch gap" zero-days at the time of the observed activity. This means they were known and fixed in upstream Chromium source code—a change containing the fix for CVE-2026-85046 was committed on August 7—but remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public for weeks. This patch gap spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge.

Proofpoint researchers noted that "it is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain" through reverse engineering. The attacks lacked the stealth found in many campaigns, as hackers typically want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. One reason for the widely used and visible exploit chain was to take advantage of this patch gap in the Chromium supply chain.

AI-Driven Exploit Development Changes the Game

The rapid development and widespread sharing of the BlueMoon exploit kit across multiple threat actors within days may reflect AI-driven exploits increasingly enabling faster vulnerability discovery and weaponization. Proofpoint hypothesized that the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans, likely pushed the attackers to move quickly before a window of opportunity closed.

Source: Ars Technica

Source: Ars Technica

"A fully weaponized Chrome exploit chain has historically been a high-value, rare capability," Proofpoint stated. "BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development. This is particularly relevant for open-source codebases, such as Chromium, where upstream patches are publicly accessible prior to downstream consumers of the codebase applying the patch."

Attack Chain Starts with Phishing Emails

The attacks begin with phishing emails that trick victims into clicking on an actor-controlled URL. TA412's first campaign, which began on August 28, used a range of lures. Some emails purported to come from university students interested in internships at the targeted organizations, while others were more target-specific exchanges intended to build trust with individuals before ultimately sending a malicious link via email.

Once a victim clicks the malicious link, the two V8 bugs trigger to allow remote code execution and escape the browser sandbox. The attack chain then exploits the Windows privilege escalation bug to download multiple payloads including browser-surveillance tools, credential-stealing backdoors, and other malware, depending on the group using the exploit kit.

Future Implications and Continued Threats

While BlueMoon leaves plenty of indications that it's being used and all three vulnerabilities have been patched, Proofpoint warned the kit may nonetheless continue to be used. "Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers," the researchers said. Organizations should watch for the continued evolution of AI-driven exploit development, which may lower barriers to entry for sophisticated attack capabilities and shorten the window between vulnerability disclosure and widespread exploitation.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved