Multiple espionage-focused threat clusters have adopted the BlueMoon exploit kit, chaining Chromium V8 vulnerabilities, a V8 sandbox escape, and the Windows kernel privilege-escalation flaw CVE-2026-85880 to gain code execution and elevated privileges. Older Windows 10 and Windows Server 2019/2022 builds are reported to be particularly exposed. The activity begins with phishing and has targeted U.S. NGOs, mining and commodity-trading firms, as well as government, defense, aerospace, manufacturing, financial, and commercial organizations across the United States and Southeast Asia.
TA412, also tracked as Violet Typhoon and APT31, was the first identified user and used phishing to install the GemStone malicious browser extension. Additional clusters—UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket—have reportedly used the kit to deliver browser-surveillance payloads, ShadowPad, and other loaders. Proofpoint assessed that rapid adoption by several actors, exposed development artifacts, and exploitation during patch gaps suggest a shared exploit-procurement pipeline; AI-assisted development may also have lowered the barrier to weaponizing browser exploits.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
Proofpoint observed BlueMoon exploit-chain use as recently as September 8, 2026, after activity peaked on September 2-3. The firm directly observed fewer than 20 targeted organizations globally and assessed that the actual number was likely higher.
CISA added the actively exploited Chrome V8 type-confusion vulnerability CVE-2026-85046 to its Known Exploited Vulnerabilities catalog and set a September 18 remediation deadline for U.S. federal civilian agencies.
On September 1, 2026, UTA0560 spear-phished multiple NGO customers using a Chrome-to-Windows exploit chain and deployed the GRIMWEDGE JScript backdoor. JungleBamboo/TA412 used byte-identical core exploit shellcode against a different target set on September 1-2, deploying SUPERSTOMP and the LONGTALE credential-stealing Chrome extension.
Proofpoint identified TA412, also known as Violet Typhoon or APT31, as the first confirmed BlueMoon user. The group targeted U.S. NGOs, mining firms, and commodity traders with phishing impersonating university interns and academic outreach, deploying the GemStone browser-surveillance extension.
Chromium upstream fixed the V8 vulnerabilities used by BlueMoon through a commit on August 7, 2026. The fixes were reportedly not incorporated into stable Chrome releases until before September 3, creating a patch-gap window exploited by the kit.
Proofpoint reported that at least four espionage-oriented threat clusters began using the BlueMoon browser-and-Windows exploit kit in late August 2026. The company assessed that most observed users had a suspected China nexus.
Intellexa used its custom Chrome exploitation framework with the V8 type-confusion vulnerability CVE-2025-6554 in activity observed in Saudi Arabia. Google mitigated the issue through a configuration change before later fixing it in Chrome 138.0.7204.96.
Researchers published network and email indicators for BlueMoon activity, including IP address 79.133.56.90, domains such as secboxes.com and msbenefit.com, and Cloudflare Workers and R2-hosted infrastructure. The report also provided suspicious payload paths, including ChromeUpdate.exe and krita.dll, along with associated SHA-256 hashes.
CISA added all three vulnerabilities exploited by the BlueMoon Chrome-to-Windows exploit chain to its Known Exploited Vulnerabilities catalog, expanding beyond the previously recorded listing of Chrome V8 flaw CVE-2026-85046.
All three vulnerabilities exploited by the BlueMoon kit—two Chromium flaws and a Windows kernel flaw—received patches within the 24 hours preceding the report. Proofpoint assessed that attackers exploited the lag between upstream Chromium fixes and their adoption by downstream browsers such as Chrome and Edge.
UNK_QuietRacket targeted government and financial organizations in Indonesia and Singapore using conference-themed phishing. The cluster used DNS-over-HTTPS command-and-control channels.
UNK_DoubleCheck compromised a Southeast Asian government email account to target a Vietnamese manufacturer. The operation used a Rust-based loader.
The cluster tracked as UNK_LateNight used defense-procurement-themed phishing against U.S. aerospace companies. Its campaign delivered the ShadowPad backdoor through a DLL-sideloading chain.
Proofpoint named and described BlueMoon as an exploit kit chaining Chromium V8 type-confusion flaw CVE-2026-85046, a V8 sandbox escape, and Windows kernel privilege-escalation flaw CVE-2026-85880. The Windows component reportedly affects older Windows 10 and Windows Server 2019/2022 builds and uses ALPC and Windows Notification Facility mechanisms to obtain kernel read/write access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 128 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
19 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcesecurityweek.com
Open sourcecysecurity.news
Open sourcecyberveille.ch
Open sourcethehackernews.com
Open sourcecloud.google.com
Open sourcedeveloper.chrome.com
Open sourcesynacktiv.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.