< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 20 sources · 3 days · First seen · Last updated

BlueMoon exploit kit cyber espionage campaign

Overview

Cybersecurity researchers have identified a sophisticated exploit kit named ‘BlueMoon’ designed for espionage. First observed on August 28, 2026, the kit was initially linked to the China-aligned threat actor APT31 (also known as Violet Typhoon or JungleBamboo). Within a 12-day window, the kit was rapidly adopted by at least four other espionage-motivated threat groups.

The exploit chain targets vulnerabilities in the Google Chrome V8 JavaScript and WebAssembly engine (CVE-2026-85046 and CVE-2026-87491) to bypass browser sandboxes. This is followed by the exploitation of a Windows kernel privilege-escalation zero-day (CVE-2026-85880) in the Advanced Local Procedure Call (ALPC) to gain elevated system control. Attackers appear to exploit a “patch gap” by reverse-engineering fixes from the open-source Chromium project before they reach stable browser releases.

Targeted organizations include U.S. defense contractors, NGOs, aerospace, and mining companies, as well as government agencies and manufacturers in Southeast Asia, specifically Indonesia, Singapore, and Vietnam. Researchers noted that the rapid development and deployment of the kit may have been accelerated by the use of artificial intelligence, though this remains unconfirmed.

Entities

Microsoft Windows · Google Chrome · Proofpoint · APT31 · Google

Timeline

  1. 4 days ago

    [TECHNOLOGY] 4 sources
    BlueMoon exploit kit chains Chrome and Windows zero-days

    The BlueMoon exploit kit, used by Chinese-linked threat actors like APT31, chains Chrome and Windows zero-days to target defense contractors, NGOs, and government agencies.

  2. 7 days ago

    [TECHNOLOGY] 17 sources
    BlueMoon exploit kit targets Chrome and Windows users

    The BlueMoon exploit kit, used by at least four espionage groups, chains Chrome and Windows vulnerabilities to compromise high-value targets in the U.S. and Southeast Asia via patch-gap exploitation.

Sources

android-mt.ouest-france.fr · arstechnica.com · ciol.com · csoonline.com.au · cyberinsider.com · cybernoz.com · cybersecurity-news.de · cybersecuritynews.es · digital-magazin.de · esecurityplanet.com · flagthis.com · moncloa.com · scworld.com · security.nl · securityaffairs.com · stiintasitehnica.com · techinside.com · technadu.com · thecyberexpress.com · usecim.net