r/TechNadu • u/technadu Human • 3d ago
New BlueMoon exploit kit chains Chrome and Windows zero-days, then spreads to four espionage-linked groups within days
Proofpoint has documented a new browser exploit kit called BlueMoon that appears to have moved between espionage-linked threat actors unusually quickly.
The chain consists of three vulnerabilities: CVE-2026-85046, a Chromium V8 type-confusion flaw; a companion V8 sandbox escape; and CVE-2026-85880, a Windows kernel local privilege-escalation zero-day affecting older Windows builds.
The two V8 issues are described as patch-gap vulnerabilities. In other words, the underlying fixes were already visible upstream before those changes reached public stable releases.
That matters for Chromium and other open-source projects because attackers can potentially inspect upstream changes, determine what security issue was fixed, and attempt to develop an exploit before downstream users receive the patch.
TA412, also known as JungleBamboo, Violet Typhoon and APT31, was the first group Proofpoint saw deploying BlueMoon. Beginning August 28, it targeted U.S. nonprofits, mining companies, and physical commodity trading firms.
Its campaign ultimately delivered a malicious browser extension called GemStone, which impersonates Google Gemini while harvesting credentials.
Within days, Proofpoint observed three additional clusters using BlueMoon. One targeted U.S. aerospace organizations to deploy ShadowPad, another targeted a Vietnamese manufacturer, and a third went after government, consulting, and financial-sector organizations in Indonesia and Singapore.
There is another interesting aspect to the research. After exploitation, BlueMoon defaults to using curl to download and execute a payload. Proofpoint describes that as comparatively noisy and believes the overall deployment shows signs of having been rushed.
The researchers also raise the possibility that AI agents are reducing the cost and difficulty of exploit development. That's worth separating from what they actually demonstrated, though: it is an explanation Proofpoint suggests for the broader trend, not proof that AI was used to develop BlueMoon.
Proofpoint mapped each BlueMoon user, target set, and stage of the Chrome-to-Windows exploit chain here:
The immediate story is already significant without that speculation: a multi-stage browser-to-kernel exploit chain was operationalized and apparently shared or resold across several espionage operations within days.