< Back to all clusters
[TECHNOLOGY] · United States, Vietnam, Indonesia, Singapore · 14 sources

started · updated

BlueMoon exploit kit targets Chrome and Windows users

Cybersecurity researchers have identified a new exploit kit, dubbed BlueMoon, which has been rapidly adopted by at least four espionage-motivated threat groups. The kit, first observed on August 28, 2026, by the group TA412 (also known as APT31), targets vulnerabilities in Google Chrome and Microsoft Windows to bypass browser sandboxes and gain elevated system privileges.

The attacks exploit a “patch gap,” where attackers reverse-engineer fixes available in the open-source Chromium project before they are integrated into stable browser releases. The exploit chain combines two Chromium V8 JavaScript engine vulnerabilities (CVE-2026-85046 and CVE-2026-87491) with a Windows kernel privilege-escalation zero-day (CVE-2026-85880).

Targeted organizations include U.S. defense contractors, NGOs, aerospace companies, and commodity traders, as well as government agencies and manufacturers in Southeast Asia, specifically Indonesia, Singapore, and Vietnam. Researchers suggest that the rapid development and deployment of such a sophisticated kit may have been accelerated by the use of artificial intelligence agents.

Entities

Chromium · Google · Google Chrome · Microsoft · Microsoft Windows · Proofpoint · TA412 · Volexity

Claims

What the coverage asserts, and how many sources carry each claim.