APT31 and Three Spy Groups Deploy BlueMoon Chrome-Windows
Four espionage groups, including APT31, used the new BlueMoon exploit kit in late August and early September 2026.

Four distinct espionage groups deployed a previously unknown exploit kit called BlueMoon within one week in late August and early September 2026. The kit chains vulnerabilities in Google Chrome and Microsoft Windows to install surveillance and backdoor malware on targeted systems.
The first observed attack, attributed to the China-aligned group APT31, occurred on August 28, 2026. Proofpoint stated that within days, several other clusters with a suspected link to China began using the same kit. Some usage remains unattributed, suggesting BlueMoon may not be exclusive to China-aligned actors.
The Exploit Chain Vulnerabilities
The BlueMoon exploit chain use three specific security flaws. The first is CVE-2026-85046, a type confusion vulnerability in Chrome's V8 JavaScript engine. The second is a V8 sandbox escape that has not been assigned a CVE identifier. The third is CVE-2026-85880, a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component.
Google patched CVE-2026-85046 in late August 2026. Microsoft addressed CVE-2026-85880 in its September 2026 Patch Tuesday updates. Proofpoint noted that both Chrome vulnerabilities were "patch-gap" zero-days when exploited. The fixes were available in the public Chromium source code but had not yet reached the stable releases of Chrome and other browsers.
How the BlueMoon Kit Works
Attack chains start with phishing emails containing malicious links. Clicking the link triggers the two Chrome V8 flaws in succession. This achieves code execution and escapes the browser's security sandbox. A reflectively loaded DLL then fingerprints the Windows host. If conditions are right, the kit uses the Windows ALPC flaw for local privilege escalation.
With raise privileges, shellcode injects a command into the Chrome broker process. The default command uses curl to download and execute a remote payload specified by the attacking group. Proofpoint researchers said multiple kit variants exist with subtle changes to obfuscation or telemetry, but the core exploit chain remains identical.
Four Groups and Their Campaigns
Proofpoint detailed the campaigns of four groups that used BlueMoon, beginning with APT31. The following table summarizes their targets and final payloads.
| Group | Start Date | Primary Targets | Final Payload & Technique |
|---|---|---|---|
| APT31 | August 28, 2026 | U.S. NGOs, mining, commodity trading firms | GemStone backdoor via GhostChrome-X extension bypass |
| UNK_LateNight | September 2, 2026 | U.S. Aerospace companies | ShadowPad backdoor via DLL sideloading |
| UNK_DoubleCheck | September 2, 2026 | Vietnamese manufacturing entity | Rust binary fetching DLL sideloading pair from cloud |
| UNK_QuietRacket | September 3, 2026 | Government, consulting, finance in Indonesia & Singapore | .NET assembly creating scheduled task for persistence |
AI-Assisted Development and Proliferation Risk
Proofpoint suggested the kit may have been developed with AI assistance. Evidence includes extensive logging, verbose code comments, and repeated references to Google's v8CTF challenge program. It is unknown if the exploits were genuinely developed for that framework or if the references were used to bypass AI model guardrails.
The company said it is unclear how multiple distinct threat actors obtained the kit. "Given its ease of adoption, it is likely to proliferate further," the report warned. It may be adopted by both espionage and financially motivated actors as patched browser versions roll out. Proofpoint highlighted that a fully weaponized Chrome exploit chain is historically rare and high-value, but BlueMoon was deployed and shared rapidly, possibly indicating reduced costs and barriers due to AI tools.
Patches and Post-Infection Artifacts
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026. Federal agencies have until September 18 to apply patches. Proofpoint emphasized that updating Chrome only prevents initial infection; it does not remove already-installed malware.
Organizations that may have been targeted should check for specific artifacts. These include a process tree where chrome.exe starts cmd.exe, curl.exe, and msgbox.exe. They should also look for ChromeUpdate.exe or msgbox.exe in the Windows TEMP folder, the folder C:Users\Public\stomp_ext, and specific scheduled tasks or registry keys. Proofpoint published six detection rules, numbered 2071919 through 2071924, for the kit's JavaScript loader and its command-and-control traffic.





