Proofpoint reported that the BlueMoon exploit kit chains three vulnerabilities to compromise Windows systems through Google Chrome: CVE-2026-85046, a V8 arbitrary-code-execution/type-confusion flaw; CVE-2026-87491, a V8 sandbox escape; and CVE-2026-85880, a Windows ALPC local privilege-escalation vulnerability. First observed on August 28 in China-linked TA412 operations targeting U.S. NGOs, mining companies, and commodities-trading firms, the kit was adopted by multiple espionage groups within days, exploiting the gap between Chromium source-code fixes and stable-browser patch deployment.
Chinese actors identified as UTA0560 and JungleBamboo (APT31) used the Chrome-to-Windows chain in targeted spear-phishing against NGOs. UTA0560 deployed the GRIMWEDGE JScript backdoor, while JungleBamboo used SUPERSTOMP to install the LONGTALE credential-stealing Chrome extension. Organizations should prioritize Chrome and Windows security updates, investigate targeted phishing activity involving Chrome exploitation, and hunt for the named payloads and unauthorized browser extensions, particularly in NGO, mining, and commodities-trading environments.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
The Chromium-source fix for CVE-2026-85046 reached a stable Chromium version, ending the identified source-to-stable patch gap for that flaw.
China-linked TA412 (JungleBamboo/APT31) was first observed using the BlueMoon exploit chain against U.S. NGOs, mining companies, and commodities-trading firms. The chain combined two Chrome V8 flaws with a Windows ALPC privilege-escalation vulnerability.
A patch for the Chrome V8 type-confusion vulnerability CVE-2026-85046 appeared in Chromium source code, beginning a gap before it reached stable browser releases.
UTA0560 and JungleBamboo reportedly exploited the Chrome and Windows vulnerability chain in targeted spear-phishing against NGOs. UTA0560 deployed the GRIMWEDGE JScript backdoor, while JungleBamboo used SUPERSTOMP to install the LONGTALE credential-stealing Chrome extension.
Within days of the first observed use, UNK_LateNight targeted U.S. aerospace companies and deployed ShadowPad, UNK_DoubleCheck targeted a Vietnamese manufacturer, and China-associated UNK_QuietRacket targeted government, financial, and consulting organizations in Indonesia and Singapore.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcexakep.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.