BlueMoon Exploit Kit Triggers Espionage Wave Across Four Groups

1 min read
Source: The Hacker News
BlueMoon Exploit Kit Triggers Espionage Wave Across Four Groups
Photo: The Hacker News
TL;DR Summary

Proofpoint links a new Chrome/Windows exploit kit, BlueMoon, to a wave of espionage campaigns by four groups—primarily China-aligned—using two Chrome V8 flaws (CVE-2026-85046 and CVE-2026-85880) and a Windows ALPC privilege escalation to run payloads after a phishing lure; multiple variants target NGOs, aerospace, Vietnamese manufacturing, and government/financial sectors, with DLL sideloading, Cloudflare infrastructure, and in-memory payloads observed. CISA added the Chrome flaw to Known Exploited Vulnerabilities; patching browsers may not remove implants. Indicators include process chains (chrome.exe → cmd.exe → curl.exe → msgbox.exe), ChromeUpdate.exe/msgbox.exe in %TEMP%, specific scheduled tasks (EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup, GeForceService), a registry key, and related DLL artifacts; detection rules 2071919–2071924 published.

Share this article

Reading Insights

Total Reads

1

Unique Readers

14

Time Saved

5 min

vs 6 min read

Condensed

91%

1,134104 words

Want the full story? Read the original article

Read on The Hacker News