news.mlab.sh
Back to the feed
threat-intel

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

HighCVSS 8.8
Summary

A new exploit kit, dubbed BlueMoon, is being used by multiple espionage groups, primarily with suspected links to China, to target organizations in the US and Southeast Asia. The kit chains together three vulnerabilities – a V8 type confusion flaw, a Chrome V8 sandbox escape, and a Windows privilege escalation bug – to deliver malware, including browser surveillance tools and credential stealers. The activity highlights a concerning trend of rapidly developed exploits leveraging publicly available patches, making it more accessible for threat actors, particularly those with state-sponsored backing.

At least four espionage groups, most with suspected links to China, are utilizing a new exploit kit, BlueMoon, to break into organizations’ networks in the US and Southeast Asia. Mark Kelly, a threat researcher at email security shop Proofpoint, notes that the exact number of organizations targeted remains unclear, but fewer than 20 were impacted globally. The Proofpoint team observed the kit’s initial use on August 28, when TA412, a cyberespionage group linked to China’s Ministry of State Security, used BlueMoon to target non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the US.

BlueMoon employs a multi-stage attack chain. It begins with a phishing email designed to trick victims into clicking on a malicious link. This triggers the two V8 vulnerabilities, allowing remote code execution and escape of the browser sandbox. The attack then exploits a Windows privilege escalation vulnerability (CVE-2026-85880), which Microsoft patched on Tuesday, to download multiple payloads, including browser-surveillance malware, credential-stealing backdoors, and others.

TA412’s initial campaign involved a range of lures, including emails posing as internship offers from university students and more targeted exchanges to build trust before delivering the exploit kit. The resulting malware, tracked as GemStone, allows attackers to issue commands through a command-and-control (C&C) channel, steal cookies and sensitive data, take screenshots, and inject a keylogger into a browser tab. The malware also contains a keyword monitor, which injects attacker-specified keywords into the top frame of each page and scans the HTML body for these keywords, triggering a screenshot if found.

Within days, other China-aligned spy crews, including UNK_LateNight and UNK_DoubleCheck, began using BlueMoon to target US aerospace companies and a Vietnamese manufacturing firm, respectively. UNK_QuietRacket targeted government, consulting, and financial-sector organizations in Indonesia and Singapore, utilizing lures related to Indonesian conferences.

Microsoft patched the Windows vulnerability (CVE-2026-85880) on Tuesday, and warned that it had been exploited prior to the update. Google also patched the V8 vulnerabilities in Chrome on September 3, and warned that an exploit for CVE-2026-85046 existed in the wild. The Proofpoint researchers emphasize that both V8 vulnerabilities were ‘patch-gap’ zero-days – known and fixed in upstream Chromium source code, but not yet present in the latest stable releases of Chrome and Chromium-based browsers.

“It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain,” the researchers note. The activity highlights a concerning trend of rapidly developed exploits leveraging publicly available patches, making it more accessible for threat actors, particularly those with state-sponsored backing. Proofpoint warns that BlueMoon will likely be used by both cyberspies and financially motivated attackers.

Read the full article at The Register