
Multiple state-aligned hacking groups have adopted a new exploit kit that can compromise Google Chrome users even when they run the latest stable browser version available at the time of the attack.
The campaign, independently documented by Proofpoint and Volexity, uses a shared exploit chain that combines Chrome and Windows vulnerabilities to escape the browser sandbox and install malware after a victim clicks a malicious link.
Proofpoint tracks the toolkit as BlueMoon and says it first observed China-linked threat actor TA412, also known as JungleBamboo, APT31, and Violet Typhoon, using it on August 28. Within days, at least three other espionage-focused clusters were deploying the same underlying exploit chain against organizations in the United States and Southeast Asia.
Volexity separately detected exploitation on September 1 while monitoring phishing attacks against non-governmental organizations. Its researchers found that another China-linked group, tracked as UTA0560, was using effectively the same exploit code but deploying different malware.
The attacks are notable because one of the Chrome vulnerabilities, CVE-2026-85046, had already been fixed in the public Chromium source code, but the fix had not yet reached Chrome’s stable release channel.
That created what researchers describe as a patch gap: attackers could examine the publicly available fix, determine what vulnerability it corrected, and build working exploit code while ordinary Chrome users still had no update available to protect themselves.
The vulnerability affects V8, Chrome’s JavaScript engine, and allows attackers to gain memory access inside the browser. The exploit chain then uses a separate V8 sandbox escape, identified by Volexity as CVE-2026-87491, followed by a Windows privilege-escalation flaw tracked as CVE-2026-85880.
Together, the vulnerabilities allow malicious code running inside a Chrome tab to break out of the browser’s security boundaries and execute malware on the Windows system.
The Windows stage limits the attack somewhat because it targets older Windows builds, including several Windows 10 versions, Windows Server 2019 and 2022, and the original Windows 11 21H2 release.
Proofpoint observed BlueMoon being delivered through highly targeted phishing emails aimed at NGOs, mining and commodity-trading firms, aerospace companies, government organizations, financial firms, and manufacturers.

Payloads varied by attacker. TA412 installed a malicious Chrome extension disguised as Google Gemini that Proofpoint calls GemStone and Volexity tracks as LONGTALE. The extension can log keystrokes, steal cookies and browser storage, take screenshots, monitor browsing activity, and receive commands from its operators.
Other campaigns used the same exploit chain to install the ShadowPad espionage backdoor, custom malware, or Volexity’s GRIMWEDGE JScript backdoor.

Proofpoint says the near-simultaneous adoption of BlueMoon suggests the exploit kit was made available to multiple operators rather than developed independently by each group. The company also found development artifacts that may indicate AI-assisted exploit creation, although it says there is no conclusive evidence.
Users should install Chrome and other Chromium-based browser updates as soon as they become available and keep Windows fully patched.







Leave a Reply