< Back to all clusters
[TECHNOLOGY] · United States · 4 sources

started · updated

BlueMoon exploit kit chains Chrome and Windows zero-days

Cybersecurity researchers have identified a new exploit kit named ‘BlueMoon’ that chains together multiple zero-day vulnerabilities in Google Chrome and Microsoft Windows to facilitate espionage. The kit was first observed on August 28 by the China-linked threat actor APT31 (also known as Violet Typhoon or JungleBamboo) and was subsequently adopted by several other Chinese-aligned groups within a 12-day window.

The exploit chain utilizes two vulnerabilities in the Chrome V8 JavaScript and WebAssembly engine (CVE-2026-85046 and CVE-2026-87491) to achieve sandbox escape, followed by a Windows privilege escalation vulnerability (CVE-2026-85880) in the Advanced Local Procedure Call (ALPC) to gain system control.

Targeted entities include U.S. defense contractors, NGOs, mining companies, and Southeast Asian government agencies. The rapid proliferation of the kit across multiple distinct actor clusters suggests either a highly efficient resource-sharing model or centralized development. Some technical artifacts indicate the potential use of AI in the kit’s creation, though this remains unconfirmed.

Entities

APT31 · Google Chrome · Microsoft Windows · Proofpoint