A recent cybersecurity threat has emerged with the introduction of the BlueMoon exploit kit. This kit has been employed by various espionage groups in what appears to be hasty and opportunistic deployments, as reported by cybersecurity firm Proofpoint. The kit has quickly gained traction, exploiting zero-day vulnerabilities in both Chrome and Windows systems.
Key Players in BlueMoon’s Initial Deployment
The exploit kit was first utilized by the China-linked Advanced Persistent Threat (APT) group Violet Typhoon, also known by several other names including APT31 and JungleBamboo. Their initial use of BlueMoon was recorded on August 28. Following this, multiple Chinese threat actors adopted the kit, although its use may not be limited to these groups alone.
According to Proofpoint, it is unclear how these distinct groups obtained the kit. However, its ease of adoption suggests that it may soon be embraced by both espionage-driven and financially motivated actors. The BlueMoon kit’s rapid adoption is attributed to its ability to chain together three unpatched vulnerabilities at the time of its emergence.
Exploiting Zero-Day Vulnerabilities
The vulnerabilities exploited by BlueMoon include two zero-day flaws in Chrome, identified as CVE-2026-85046 and CVE-2026-87491. These flaws, affecting the V8 JavaScript and WebAssembly engine, were patched on September 3 and September 8 respectively. Additionally, a Windows zero-day tracked as CVE-2026-85880, involving a privilege escalation in Windows Advanced Local Procedure Call (ALPC), was addressed in the September 2026 Patch Tuesday updates.
Proofpoint notes that BlueMoon exploits these vulnerabilities for sandbox escape, followed by host fingerprinting and privilege escalation code execution. The exploit kit then injects a CreateProcess stub into the parent Chrome broker process, facilitating the download and execution of an executable via a curl command.
Adoption and Impact of BlueMoon
BlueMoon has been identified in several variations, all utilizing the same central exploit chain and orchestration methods. Development artifacts suggest the possible use of AI in its creation, although no definitive evidence confirms this. Initially, Violet Typhoon deployed BlueMoon against NGOs in the US and firms in the mining and trading sectors.
In early September, other China-linked espionage groups such as UNK_LateNight and UNK_DoubleCheck began using BlueMoon against US aerospace companies and a manufacturing organization in Vietnam, respectively. Another group, UNK_QuietRacket, targeted government, consulting, and financial entities in Indonesia and Singapore the following day.
Proofpoint highlights that BlueMoon’s rapid development and distribution across multiple threat actors indicate a lower barrier to entry for such capabilities. This trend is partly driven by AI agents enabling faster exploit development.
The BlueMoon exploit kit represents a significant risk, highlighting the need for ongoing vigilance and timely patching of vulnerabilities to protect against emerging threats.
