BlueMoon Exploit Kit Targets Windows and Chrome Zero-Day Flaws
Multiple cyber-espionage groups have deployed an exploit kit called BlueMoon that targets zero-day vulnerabilities in Microsoft Windows and Google Chrome. The BlueMoon exploit kit combines two security flaws in Chromium-based browsers that enable remote code execution and sandbox escape, paired with a kernel local privilege escalation vulnerability in Windows. Researchers at Proofpoint and Volexity have documented distinct attack campaigns using this modular tool since late August, with activity linked to multiple threat actors including Chinese state-sponsored groups and other organized hacking operations.
How BlueMoon Works and Who’s Using It
The BlueMoon exploit kit operates by running exploits inside a Web Worker, retrying the attack up to five times. It fingerprints the target system, exploits the Windows privilege elevation flaw to elevate the Chrome renderer process, and injects code into Chrome’s parent process to execute operator-selected commands. The default final payload uses curl to download and execute an executable—typically a malware loader—from the temporary directory. Researchers observed the kit being used since August 28 in spearphishing campaigns attributed to JungleBamboo (also known as APT31, Violet Typhoon, and Tide Castle), a threat actor associated with China. Volexity documented similar activity on September 1st from another group tracked as UTA0560, which targeted customers at multiple non-governmental organizations.

Exploitation Timeline and Attack Clusters
According to Proofpoint, attackers exploited CVE-2026-85880 as a zero-day, with evidence suggesting the vulnerability has been leveraged since 2025 and repackaged into BlueMoon. The local privilege escalation DLL carries a compilation timestamp from 2025 and appears unforged, suggesting the exploit creator adapted an existing capability into the kit. The developers of BlueMoon take advantage of the delay between public Chromium fixes and stable Chrome releases by reverse-engineering code changes and creating exploits targeting downstream users. Both security firms identified four distinct activity clusters associated with BlueMoon deployments. JungleBamboo is known for targeting NGOs in the US and mining companies using the Longtale/GemStone credential stealer. UTA0560 deployed Grimwedge, an in-memory JScript backdoor for reconnaissance and command execution. A third cluster, UNK_LateNight, deployed ShadowPad on U.S. aerospace and defense-industrial-base systems. A fourth group, UNK_DoubleCheck, targeted Vietnamese manufacturing firms with an in-memory Rust loader. As covered earlier, CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks highlighted similar zero-day exploitation patterns affecting critical infrastructure. In a related development, NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions demonstrated how attackers continue to weaponize legitimate tools for initial access. Proofpoint expects BlueMoon adoption to increase and potentially reach financially motivated attackers, advising defenders to use provided indicators of compromise to block activity early.
المصدر: BleepingComputer