BlueMoon Exploit Kit Triggers Espionage Wave Across Four Groups

Proofpoint links a new Chrome/Windows exploit kit, BlueMoon, to a wave of espionage campaigns by four groups—primarily China-aligned—using two Chrome V8 flaws (CVE-2026-85046 and CVE-2026-85880) and a Windows ALPC privilege escalation to run payloads after a phishing lure; multiple variants target NGOs, aerospace, Vietnamese manufacturing, and government/financial sectors, with DLL sideloading, Cloudflare infrastructure, and in-memory payloads observed. CISA added the Chrome flaw to Known Exploited Vulnerabilities; patching browsers may not remove implants. Indicators include process chains (chrome.exe → cmd.exe → curl.exe → msgbox.exe), ChromeUpdate.exe/msgbox.exe in %TEMP%, specific scheduled tasks (EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup, GeForceService), a registry key, and related DLL artifacts; detection rules 2071919–2071924 published.
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week The Hacker News
- 4 groups caught using the same Chrome and Windows exploit kit Ars Technica
- Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days Proofpoint
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox The Hacker News
- Google warns of new Chrome zero-day bug exploited in attacks BleepingComputer
Reading Insights
1
14
5 min
vs 6 min read
91%
1,134 → 104 words
Want the full story? Read the original article
Read on The Hacker News