Skip to content
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
nextbyte.live nextbyte.live
nextbyte.live nextbyte.live
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
Subscribe
Close

Search

nextbyte.live nextbyte.live
nextbyte.live nextbyte.live
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
BlueMoon Exploit Kit Targets Windows and Chrome Zero-Day Flaws
cybersecurity

BlueMoon Exploit Kit Targets Windows and Chrome Zero-Day Flaws

By abde el aziz
September 11, 2026 2 Min Read
0

Multiple cyber-espionage groups have deployed an exploit kit called BlueMoon that targets zero-day vulnerabilities in Microsoft Windows and Google Chrome. The BlueMoon exploit kit combines two security flaws in Chromium-based browsers that enable remote code execution and sandbox escape, paired with a kernel local privilege escalation vulnerability in Windows. Researchers at Proofpoint and Volexity have documented distinct attack campaigns using this modular tool since late August, with activity linked to multiple threat actors including Chinese state-sponsored groups and other organized hacking operations.

Table of Contents

  • How BlueMoon Works and Who’s Using It
  • Exploitation Timeline and Attack Clusters

How BlueMoon Works and Who’s Using It

The BlueMoon exploit kit operates by running exploits inside a Web Worker, retrying the attack up to five times. It fingerprints the target system, exploits the Windows privilege elevation flaw to elevate the Chrome renderer process, and injects code into Chrome’s parent process to execute operator-selected commands. The default final payload uses curl to download and execute an executable—typically a malware loader—from the temporary directory. Researchers observed the kit being used since August 28 in spearphishing campaigns attributed to JungleBamboo (also known as APT31, Violet Typhoon, and Tide Castle), a threat actor associated with China. Volexity documented similar activity on September 1st from another group tracked as UTA0560, which targeted customers at multiple non-governmental organizations.

BlueMoon Exploit Kit Targets Windows and Chrome Zero-Day Flaws

Exploitation Timeline and Attack Clusters

According to Proofpoint, attackers exploited CVE-2026-85880 as a zero-day, with evidence suggesting the vulnerability has been leveraged since 2025 and repackaged into BlueMoon. The local privilege escalation DLL carries a compilation timestamp from 2025 and appears unforged, suggesting the exploit creator adapted an existing capability into the kit. The developers of BlueMoon take advantage of the delay between public Chromium fixes and stable Chrome releases by reverse-engineering code changes and creating exploits targeting downstream users. Both security firms identified four distinct activity clusters associated with BlueMoon deployments. JungleBamboo is known for targeting NGOs in the US and mining companies using the Longtale/GemStone credential stealer. UTA0560 deployed Grimwedge, an in-memory JScript backdoor for reconnaissance and command execution. A third cluster, UNK_LateNight, deployed ShadowPad on U.S. aerospace and defense-industrial-base systems. A fourth group, UNK_DoubleCheck, targeted Vietnamese manufacturing firms with an in-memory Rust loader. As covered earlier, CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks highlighted similar zero-day exploitation patterns affecting critical infrastructure. In a related development, NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions demonstrated how attackers continue to weaponize legitimate tools for initial access. Proofpoint expects BlueMoon adoption to increase and potentially reach financially motivated attackers, advising defenders to use provided indicators of compromise to block activity early.

المصدر: BleepingComputer

Author

abde el aziz

Follow Me
Other Articles
Apple Watch Series 12 and Ultra 4 Debut with AI Audio Intelligence
Previous

Apple Watch Series 12 and Ultra 4 Debut with AI Audio Intelligence

Google launches Gemini app for Windows
Next

Google launches Gemini app for Windows

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • New BambooToken Malware Uses MQTT to Control Windows and Linux Systems
  • Apple rolls out iOS 27 with Siri AI beta
  • Is the GTA 6 Ultimate Edition worth the extra cost?
  • Apple CEO discusses why iPhone Duo foldable arrived after Android rivals
  • Google launches Gemini app for Windows

Recent Comments

  1. New BambooToken Malware Uses MQTT to Control Windows and Linux Systems on CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks
  2. Apple rolls out iOS 27 with Siri AI beta on Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
  3. Is the GTA 6 Ultimate Edition worth the extra cost? on Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
  4. Apple CEO discusses why iPhone Duo foldable arrived after Android rivals on The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent
  5. Google launches Gemini app for Windows on Google AI Mode adds flight price tracking and hotel booking tools

Archives

  • September 2026
  • August 2026

Categories

  • ai
  • crypto
  • cybersecurity
  • gadgets
  • hardware
  • tech
  • web
Copyright 2026 — nextbyte.live. All rights reserved. Blogsy WordPress Theme