BlueMoon: Four Espionage Groups Share One Chrome-to-SYSTEM Exploit Kit

By George Bailey   Published: 09/09/26   Updated: 09/09/26   3 min read

What Changed

Proofpoint disclosed on September 9 that at least four espionage-motivated clusters rapidly adopted a shared browser and Windows exploit kit tracked as BlueMoon. The chain combines a Chromium V8 type-confusion bug (CVE-2026-85046), an unnumbered V8 sandbox escape, and a Windows kernel local privilege escalation (CVE-2026-85880) that Microsoft describes as an Advanced Local Procedure Call (ALPC) heap-overflow path to SYSTEM. CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalog on September 4 and CVE-2026-85880 on September 8 with September Patch Tuesday.

Both V8 issues were patch-gap zero-days during the observed campaigns: fixed in public Chromium source before they landed in stable Chrome and Edge builds. The CVE-2026-85046 fix committed upstream on August 7 and did not reach general stable Chromium until September 3—nearly four weeks of public diff with no consumer patch. That is the window BlueMoon was built to use.

Observed adopters include China-aligned TA412 (from August 28, targeting U.S. NGOs, mining, and commodity trading), UNK_LateNight (U.S. aerospace with ShadowPad follow-on), UNK_QuietRacket (Singapore and Indonesia government and finance), and UNK_DoubleCheck (Vietnamese manufacturing). Delivery is spearphish to an actor-controlled landing page, BlueMoon execution, then a default curl download-and-execute of operator malware. Payloads diverge by actor: a fake “Google Gemini” browser extension tracked as GemStone, ShadowPad, Rust loaders, and custom DLL sideloading.

Why This Matters Operationally

A fully weaponized Chrome chain used to be scarce and carefully husbanded. BlueMoon looks like the opposite: noisy defaults, verbose logging, markdown-handover comments, and same-day infrastructure spun up for campaigns. Proofpoint’s working hypothesis is blunt—AI-assisted reverse engineering of public Chromium patches is collapsing the cost of “rare” browser kits, and open-source patch gaps are the accelerant.

For operators, that changes triage math. Chromium-family browsers—Chrome, Edge, Brave, Vivaldi—are the front door. Older Windows builds still common on desktops and some servers (builds 17763, 19041–19045, 20348, and 22000) remain in the LPE target set. Once four distinct clusters share a kit, financially motivated actors are next. That is not a theoretical worry; it is the adoption pattern Proofpoint already flags.

What Defenders Should Verify First

Source Context

The operational conclusion: close the Chromium patch gap on every managed browser, patch the ALPC elevation of privilege, and hunt for a kit that was designed to be easy to re-skin—not quiet.

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.