Recent findings reveal that multiple espionage-focused groups have deployed a new exploit kit, BlueMoon, targeting vulnerabilities in Microsoft Windows and Google Chrome. The kit, which chains together multiple vulnerabilities, was first identified in use by APT31, a China-aligned group, on August 28, 2026, according to a report by Proofpoint.
Widespread Use of BlueMoon Exploit Kit
Just days after APT31’s initial deployment of BlueMoon, other espionage-driven groups began leveraging the same exploit kit. While many of these groups are suspected to have ties to China, BlueMoon’s use is not limited to China-aligned actors. The exploit kit’s widespread adoption highlights its accessibility and potential appeal to a variety of threat actors.
The BlueMoon exploit chain involves three significant vulnerabilities: CVE-2026-85046, a type confusion flaw in Google Chrome’s V8 engine; an unassigned V8 sandbox escape; and CVE-2026-85880, a heap-based buffer overflow in Windows ALPC. While some of these vulnerabilities have been patched, the ‘patch-gap’ allowed attackers to exploit the flaws before they were addressed in stable releases.
Attack Methodology and Phishing Tactics
Phishing emails serve as the primary method of initiating BlueMoon attacks. Victims are lured to actor-controlled URLs that trigger the Chrome vulnerabilities, allowing attackers to execute code and escape the browser’s sandbox. This is followed by exploiting a Windows privilege escalation bug to inject shellcode for downloading multiple payloads.
Proofpoint researchers noted that the attack chain employs reflectively loaded DLLs to fingerprint Windows hosts and decide on further exploitation steps. The subsequent phases involve elevating privileges and executing commands to download and run malicious executables.
Variations and Implications of the Exploit Kit
Several BlueMoon variants have been detected, each with slight modifications to evade detection or tailor attacks to specific campaigns. Despite these changes, the core exploit chain remains consistent, indicating a resilient and adaptable threat.
The presence of detailed logging and verbose comments suggests that artificial intelligence tools may have assisted in the kit’s development. Additionally, references to Google’s v8CTF challenge imply possible links to exploit-focused reward programs.
Proofpoint’s report raises concerns about the ease with which distinct threat actors have accessed BlueMoon. Its rapid adoption and sharing among various groups underscore the potential for further proliferation as more actors take advantage of its capabilities.
Future Outlook and Mitigation Strategies
The emergence of BlueMoon exemplifies the growing sophistication of cyber threats and the urgency for timely patching of vulnerabilities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included the Chrome flaw in its Known Exploited Vulnerabilities catalog, urging federal agencies to patch by September 18, 2026.
While updating Chrome can block new exploits, existing infections may persist. Users are advised to check for suspicious processes, files, scheduled tasks, and registry keys to detect and mitigate potential threats. Proofpoint has also released detection rules to aid in identifying malicious activity related to BlueMoon.
