Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 20 sources · 3 days · First seen · Last updated
BlueMoon exploit kit cyber espionage campaign
Overview
Cybersecurity researchers have identified a sophisticated exploit kit named ‘BlueMoon’ designed for espionage. First observed on August 28, 2026, the kit was initially linked to the China-aligned threat actor APT31 (also known as Violet Typhoon or JungleBamboo). Within a 12-day window, the kit was rapidly adopted by at least four other espionage-motivated threat groups.
The exploit chain targets vulnerabilities in the Google Chrome V8 JavaScript and WebAssembly engine (CVE-2026-85046 and CVE-2026-87491) to bypass browser sandboxes. This is followed by the exploitation of a Windows kernel privilege-escalation zero-day (CVE-2026-85880) in the Advanced Local Procedure Call (ALPC) to gain elevated system control. Attackers appear to exploit a “patch gap” by reverse-engineering fixes from the open-source Chromium project before they reach stable browser releases.
Targeted organizations include U.S. defense contractors, NGOs, aerospace, and mining companies, as well as government agencies and manufacturers in Southeast Asia, specifically Indonesia, Singapore, and Vietnam. Researchers noted that the rapid development and deployment of the kit may have been accelerated by the use of artificial intelligence, though this remains unconfirmed.
Entities
Microsoft Windows · Google Chrome · Proofpoint · APT31 · Google
Timeline
-
4 days ago
[TECHNOLOGY] 4 sourcesBlueMoon exploit kit chains Chrome and Windows zero-daysThe BlueMoon exploit kit, used by Chinese-linked threat actors like APT31, chains Chrome and Windows zero-days to target defense contractors, NGOs, and government agencies.
-
7 days ago
[TECHNOLOGY] 17 sourcesBlueMoon exploit kit targets Chrome and Windows usersThe BlueMoon exploit kit, used by at least four espionage groups, chains Chrome and Windows vulnerabilities to compromise high-value targets in the U.S. and Southeast Asia via patch-gap exploitation.
Sources
android-mt.ouest-france.fr · arstechnica.com · ciol.com · csoonline.com.au · cyberinsider.com · cybernoz.com · cybersecurity-news.de · cybersecuritynews.es · digital-magazin.de · esecurityplanet.com · flagthis.com · moncloa.com · scworld.com · security.nl · securityaffairs.com · stiintasitehnica.com · techinside.com · technadu.com · thecyberexpress.com · usecim.net