Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

Posted on September 12, 2026 By CWS

A recent cybersecurity threat has emerged with the introduction of the BlueMoon exploit kit. This kit has been employed by various espionage groups in what appears to be hasty and opportunistic deployments, as reported by cybersecurity firm Proofpoint. The kit has quickly gained traction, exploiting zero-day vulnerabilities in both Chrome and Windows systems.

Key Players in BlueMoon’s Initial Deployment

The exploit kit was first utilized by the China-linked Advanced Persistent Threat (APT) group Violet Typhoon, also known by several other names including APT31 and JungleBamboo. Their initial use of BlueMoon was recorded on August 28. Following this, multiple Chinese threat actors adopted the kit, although its use may not be limited to these groups alone.

According to Proofpoint, it is unclear how these distinct groups obtained the kit. However, its ease of adoption suggests that it may soon be embraced by both espionage-driven and financially motivated actors. The BlueMoon kit’s rapid adoption is attributed to its ability to chain together three unpatched vulnerabilities at the time of its emergence.

Exploiting Zero-Day Vulnerabilities

The vulnerabilities exploited by BlueMoon include two zero-day flaws in Chrome, identified as CVE-2026-85046 and CVE-2026-87491. These flaws, affecting the V8 JavaScript and WebAssembly engine, were patched on September 3 and September 8 respectively. Additionally, a Windows zero-day tracked as CVE-2026-85880, involving a privilege escalation in Windows Advanced Local Procedure Call (ALPC), was addressed in the September 2026 Patch Tuesday updates.

Proofpoint notes that BlueMoon exploits these vulnerabilities for sandbox escape, followed by host fingerprinting and privilege escalation code execution. The exploit kit then injects a CreateProcess stub into the parent Chrome broker process, facilitating the download and execution of an executable via a curl command.

Adoption and Impact of BlueMoon

BlueMoon has been identified in several variations, all utilizing the same central exploit chain and orchestration methods. Development artifacts suggest the possible use of AI in its creation, although no definitive evidence confirms this. Initially, Violet Typhoon deployed BlueMoon against NGOs in the US and firms in the mining and trading sectors.

In early September, other China-linked espionage groups such as UNK_LateNight and UNK_DoubleCheck began using BlueMoon against US aerospace companies and a manufacturing organization in Vietnam, respectively. Another group, UNK_QuietRacket, targeted government, consulting, and financial entities in Indonesia and Singapore the following day.

Proofpoint highlights that BlueMoon’s rapid development and distribution across multiple threat actors indicate a lower barrier to entry for such capabilities. This trend is partly driven by AI agents enabling faster exploit development.

The BlueMoon exploit kit represents a significant risk, highlighting the need for ongoing vigilance and timely patching of vulnerabilities to protect against emerging threats.

Security Week News Tags:AI in cybersecurity, APT31, BlueMoon, Chrome zero-day, Cybersecurity, espionage groups, exploit kit, Proofpoint, Violet Typhoon, Windows zero-day

Post navigation

Previous Post: How AI Adoption Transforms Security Operations Centers
Next Post: AI-Driven Cyber Threats Demand Swift Security Upgrades

Related Posts

Malicious NPM Packages Disguised as Express Utilities Allow Attackers to Wipe Systems Malicious NPM Packages Disguised as Express Utilities Allow Attackers to Wipe Systems Security Week News
Minnesota Water Systems Targeted by Cyberattacks Amid Iranian Hacker Concerns Minnesota Water Systems Targeted by Cyberattacks Amid Iranian Hacker Concerns Security Week News
Jaguar Land Rover Says Shutdown Will Continue Until at Least Oct 1 After Cyberattack Jaguar Land Rover Says Shutdown Will Continue Until at Least Oct 1 After Cyberattack Security Week News
China’s Military Tightens Cybersecurity Vendor Restrictions China’s Military Tightens Cybersecurity Vendor Restrictions Security Week News
Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks Salesforce and ServiceNow Hit by ‘City-Forum’ Cyber Attacks Security Week News
DHS Database Breach and Adobe’s Security Enhancements DHS Database Breach and Adobe’s Security Enhancements Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days
  • How AI Adoption Transforms Security Operations Centers
  • OpenAI Agents Implicated in RubyGems Attack
  • AI Agents Exploit RubyGems in Massive Package Upload

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days
  • How AI Adoption Transforms Security Operations Centers
  • OpenAI Agents Implicated in RubyGems Attack
  • AI Agents Exploit RubyGems in Massive Package Upload

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark