BlueMoon is a browser-and-Windows exploit kit used in targeted espionage campaigns beginning in late August 2026. It chains Chromium V8 remote code execution, a V8 sandbox escape, and the Windows kernel local privilege-escalation vulnerability CVE-2026-85880 to compromise Chrome browsers, escape the renderer sandbox, elevate privileges, and execute an attacker-selected payload. Its default post-exploitation behavior downloads and runs a payload using a command-line retrieval utility. The Windows privilege-escalation component has been associated with older Windows 10, Windows Server 2019/2022, and early Windows 11 builds.
At least four distinct threat clusters used substantially identical BlueMoon builds: TA412 (also known as APT31 and Violet Typhoon), UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket. Most observed activity has been assessed as China-aligned, although exclusive Chinese control or distribution of the kit has not been established. Campaigns targeted U.S. NGOs, mining and commodity-trading organizations, aerospace and defense companies, a Vietnamese manufacturer, and government, consulting, and financial-sector entities in Indonesia and Singapore. Delivery was associated with spearphishing lures, including internship, academic-conference, procurement, vaccination, and regional conference themes. BlueMoon campaigns deployed actor-specific follow-on malware, including the GemStone browser-surveillance extension, ShadowPad, and loader chains. Rapid multi-actor adoption suggests a shared exploit-procurement or distribution channel, but its source remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Security researchers at Proofpoint have named the kit “BlueMoon,” identifying its use by at least four distinct threat clusters since late August 2026.
Security researchers at Proofpoint have named the kit “BlueMoon,” identifying its use by at least four distinct threat clusters since late August 2026.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Security researchers at Proofpoint have named the kit “BlueMoon,” identifying its use by at least four distinct threat clusters since late August 2026.
The groups were observed using the same exploit kit, dubbed BlueMoon by Proofpoint, to compromise Chrome browsers and deploy malware.
Security researchers at Proofpoint have named the kit “BlueMoon,” identifying its use by at least four distinct threat clusters since late August 2026.
Security researchers at Proofpoint have named the kit “BlueMoon,” identifying its use by at least four distinct threat clusters since late August 2026.
The groups were observed using the same exploit kit, dubbed BlueMoon by Proofpoint, to compromise Chrome browsers and deploy malware.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
If the target clicked on the provided link to the actor-controlled domain hosting the exploits, they were shown a loading page for several seconds while the browser exploit was attempted.
TA412 targeted U.S. NGOs, mining companies and commodity traders using lures including fake internship inquiries and messages about an Asian Studies conference. UNK_LateNight used fake procurement inquiries, while UNK_QuietRacket used fake Indonesian conference invitations.
Observed variants encoded or obfuscated BlueMoon components. UNK_DoubleCheck RC4-decrypts SysPr.prx, while UNK_QuietRacket Base64-decodes and ChaCha20-decrypts its C2-delivered payload.
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A browser-to-kernel exploit kit that chains Chromium V8 remote code execution and sandbox-escape vulnerabilities with a Windows local privilege-escalation flaw. Its default payload downloads and executes an attacker-supplied file using curl.
A browser-to-kernel exploit kit chaining Chromium V8 remote-code-execution and sandbox-escape vulnerabilities with a Windows kernel privilege-escalation flaw. Its default payload downloads and executes an attacker-supplied file via curl.
A shared exploit kit that chains two Chrome/browser flaws with a Windows vulnerability to take control of victim computers, then downloads and hands execution to a payload selected by the operator. It was used during the Chromium-to-Chrome stable-release patch gap.
A browser exploit kit used in spearphishing campaigns. It exploits Chrome/Chromium V8 type confusion for renderer RCE, escapes the V8 sandbox, and conditionally exploits a Windows kernel LPE to escape the renderer sandbox and inject a command into the Chrome broker process. Its default post-exploitation action uses curl to download and execute an actor-provided executable.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.