started · updated
BlueMoon exploit kit targets Chrome and Windows users
Cybersecurity researchers have identified a new exploit kit, dubbed BlueMoon, which has been rapidly adopted by at least four espionage-motivated threat groups. The kit, first observed on August 28, 2026, by the group TA412 (also known as APT31), targets vulnerabilities in Google Chrome and Microsoft Windows to bypass browser sandboxes and gain elevated system privileges.
The attacks exploit a “patch gap,” where attackers reverse-engineer fixes available in the open-source Chromium project before they are integrated into stable browser releases. The exploit chain combines two Chromium V8 JavaScript engine vulnerabilities (CVE-2026-85046 and CVE-2026-87491) with a Windows kernel privilege-escalation zero-day (CVE-2026-85880).
Targeted organizations include U.S. defense contractors, NGOs, aerospace companies, and commodity traders, as well as government agencies and manufacturers in Southeast Asia, specifically Indonesia, Singapore, and Vietnam. Researchers suggest that the rapid development and deployment of such a sophisticated kit may have been accelerated by the use of artificial intelligence agents.
Entities
Chromium · Google · Google Chrome · Microsoft · Microsoft Windows · Proofpoint · TA412 · Volexity
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] Artificial intelligence may have aided in the development of the BlueMoon exploit kit. www.scworld.com · arstechnica.com · www.techinside.com · www.technadu.com
- [● 3 SOURCES] The exploit kit targeted U.S. defense contractors, NGOs, and government agencies in Southeast Asia. www.scworld.com · www.techinside.com · www.esecurityplanet.com
- [● 5 SOURCES] Attackers exploited a patch gap between the availability of fixes in the open-source Chromium project and stable Chrome releases. www.scworld.com · cyberinsider.com · arstechnica.com · www.technadu.com · www.esecurityplanet.com
- [● 9 SOURCES] At least four espionage-motivated threat groups have used the BlueMoon exploit kit since late August 2026. www.scworld.com · cyberinsider.com · securityaffairs.com · www.technadu.com · arstechnica.com · +3 more
- [● 6 SOURCES] The exploit chain includes CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. cyberinsider.com · www.technadu.com · android-mt.ouest-france.fr · securityaffairs.com · www.esecurityplanet.com
- [● 6 SOURCES] The group TA412, also known as APT31, was the first observed cluster to use the kit on August 28, 2026. cyberinsider.com · www.technadu.com · android-mt.ouest-france.fr · securityaffairs.com · www.esecurityplanet.com
- [● 6 SOURCES] The kit allows attackers to escape the browser sandbox and gain system privileges on Windows machines. cyberinsider.com · www.scworld.com · www.technadu.com · www.esecurityplanet.com · arstechnica.com
- [● 7 SOURCES] The BlueMoon exploit kit chains two Chromium V8 vulnerabilities with a Windows kernel privilege-escalation zero-day. cyberinsider.com · securityaffairs.com · www.technadu.com · arstechnica.com · www.scworld.com · +1 more