What Changed
Proofpoint disclosed on September 9 that at least four espionage-motivated clusters rapidly adopted a shared browser and Windows exploit kit tracked as BlueMoon. The chain combines a Chromium V8 type-confusion bug (CVE-2026-85046), an unnumbered V8 sandbox escape, and a Windows kernel local privilege escalation (CVE-2026-85880) that Microsoft describes as an Advanced Local Procedure Call (ALPC) heap-overflow path to SYSTEM. CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog on September 4 and CVE-2026-85880 on September 8 with September Patch Tuesday.
Both V8 issues were patch-gap zero-days during the observed campaigns: fixed in public Chromium source before they landed in stable Chrome and Edge builds. The CVE-2026-85046 fix committed upstream on August 7 and did not reach general stable Chromium until September 3—nearly four weeks of public diff with no consumer patch. That is the window BlueMoon was built to use.
Observed adopters include China-aligned TA412 (from August 28, targeting U.S. NGOs, mining, and commodity trading), UNK_LateNight (U.S. aerospace with ShadowPad follow-on), UNK_QuietRacket (Singapore and Indonesia government and finance), and UNK_DoubleCheck (Vietnamese manufacturing). Delivery is spearphish to an actor-controlled landing page, BlueMoon execution, then a default curl download-and-execute of operator malware. Payloads diverge by actor: a fake “Google Gemini” browser extension tracked as GemStone, ShadowPad, Rust loaders, and custom DLL sideloading.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Why This Matters Operationally
A fully weaponized Chrome chain used to be scarce and carefully husbanded. BlueMoon looks like the opposite: noisy defaults, verbose logging, markdown-handover comments, and same-day infrastructure spun up for campaigns. Proofpoint’s working hypothesis is blunt—AI-assisted reverse engineering of public Chromium patches is collapsing the cost of “rare” browser kits, and open-source patch gaps are the accelerant.
For operators, that changes triage math. Chromium-family browsers—Chrome, Edge, Brave, Vivaldi—are the front door. Older Windows builds still common on desktops and some servers (builds 17763, 19041–19045, 20348, and 22000) remain in the LPE target set. Once four distinct clusters share a kit, financially motivated actors are next. That is not a theoretical worry; it is the adoption pattern Proofpoint already flags.
What Defenders Should Verify First
- Force Chromium to current stable across Chrome, Edge, and other managed browsers. Confirm build dates after the September 3 Chromium stable that absorbed CVE-2026-85046; do not trust “auto-update is on” without inventory evidence.
- Apply September 2026 Windows updates that remediate CVE-2026-85880. Prioritize fleets still on Windows 10, Server 2019, and early Windows 11 21H2 builds listed in BlueMoon’s LPE gate.
- Hunt the default process tree:
chrome.exe→cmd.exe→curl.exe→%TEMP%\msgbox.exe(orChromeUpdate.exe). SessionStorage keys namedv8ctf_exp_attemptare a high-signal browser artifact. - Look for GemStone / fake Gemini extensions, Secure Preferences HMAC forgery side effects, and scheduled tasks such as
EdgeCore_AutoUpdate,GeForceService, andMicrosoftEdgeUpdatesTaskMachine. - Block or closely monitor Proofpoint-published delivery and C2 domains, including Cloudflare Workers spoofing aerospace brands, conference themes, and “extension management portal” hosts.
- Treat spearphish that “loads then redirects to a real site” as exploit delivery, not just credential phishing—especially internship, RFQ/aerospace, and conference lures.
Source Context
- Proofpoint: Once in a BlueMoon (Sep 9, 2026)
- Ars Technica: Four groups using the same Chrome/Windows kit
- CISA KEV: CVE-2026-85046 (Sep 4, 2026)
- CISA KEV: CVE-2026-85880 among Sep 8 additions
- CrowdStrike: September 2026 Patch Tuesday analysis
The operational conclusion: close the Chromium patch gap on every managed browser, patch the ALPC elevation of privilege, and hunt for a kit that was designed to be easy to re-skin—not quiet.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.