BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days
A new exploit kit called BlueMoon, which chains three recent zero-day vulnerabilities in Chrome and Windows, has been rapidly adopted by multiple Chinese

Multiple Chinese espionage groups have been deploying a new exploit kit named BlueMoon in what appears to be rushed and opportunistic campaigns. Cybersecurity firm Proofpoint reports that the kit chains together three vulnerabilities that were unpatched at the time of its emergence.
The Zero-Day Vulnerabilities
The BlueMoon exploit kit use two Chrome zero-days and one Windows zero-day. The Chrome flaws, tracked as CVE-2026-85046 and CVE-2026-87491, impact the V8 JavaScript and WebAssembly engine. Google patched them as zero-days on September 3 and September 8, respectively. The Windows vulnerability, tracked as CVE-2026-85880, is a privilege escalation flaw in the Windows Advanced Local Procedure Call (ALPC) component, which Microsoft fixed on the September 2026 Patch Tuesday.
Proofpoint states that BlueMoon exploits the V8 defects to escape the Chrome sandbox. It then fingerprints the host and executes the privilege escalation code. Finally, it injects a CreateProcess stub into the parent Chrome broker process to download and execute a malicious payload via a curl command.
Rapid Adoption by Threat Actors
The China-linked group known as Violet Typhoon, also tracked as APT31, was the first to use BlueMoon on August 28. Its targets included non-governmental organizations in the United States, as well as mining entities and physical commodity trading firms. Within days, several other Chinese threat actors began using the kit.
A second China-linked espionage group, tracked as UNK_LateNight, started using BlueMoon on September 2 against multiple U.S. Aerospace companies. On the same day, a threat actor tracked as UNK_DoubleCheck targeted a manufacturing organization in Vietnam. The following day, September 3, the Chinese group UNK_QuietRacket began using it in attacks against government, consulting, and financial entities in Indonesia and Singapore.
Proofpoint notes, "It is currently unknown how multiple distinct threat actors obtained access to the exploit kit." The firm adds that given its ease of adoption, BlueMoon is likely to proliferate further and be used by both espionage-motivated and financially motivated threat actors.
Packaging and Potential AI Development
Proofpoint identified several packaging variations of the BlueMoon exploit kit, though all use the same underlying exploit chain and identical orchestration and loading mechanisms. The firm retrieved development artifacts that suggest the kit's creators might have used artificial intelligence to build it. However, Proofpoint cautions that "no single artifact conclusively confirms this."
The rapid development and sharing of the kit across multiple threat actors within days, coupled with high detection signals, may indicate a lower barrier to entry for such capabilities. Proofpoint observes, "This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development." The activity might not be exclusive to China-aligned groups, indicating potential for wider use.





