Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

proofpoint+1thehackernews+1cybersecuritynews+1At least four espionage-motivated hacking groups, most with suspected ties to Chinese state intelligence, have been caught using the same exploit kit to compromise Google Chrome Alphabet Inc. and Microsoft Windows in a rapid-fire campaign that began in late August and remains ongoing, cybersecurity firm Proofpoint disclosed on Wednesday.proofpoint
The kit, which Proofpoint named BlueMoon, chains three vulnerabilities to give attackers full control of a target's computer: a type-confusion flaw in Chrome's V8 JavaScript engine (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel privilege-escalation bug in the Advanced Local Procedure Call system (CVE-2026-85880). All attacks begin with phishing emails that lure victims to attacker-controlled URLs, triggering the exploit chain in sequence.thehackernews+2
Both Chrome-side vulnerabilities were so-called "patch-gap" zero-days — fixes existed in Chromium's public source code but had not yet reached stable browser releases, giving the exploit developer roughly a four-week window to reverse-engineer working exploits before patches reached end users. Google patched CVE-2026-85046 in Chrome on September 3, and Microsoft addressed CVE-2026-85880 as part of its September 2026 Patch Tuesday updates.cybersecuritynews+3
Proofpoint researchers flagged circumstantial evidence that AI coding tools may have assisted in BlueMoon's development, including verbose debugging comments, extensive diagnostic logging, and references to Google's v8CTF bug bounty framework throughout the code. Researchers said they could not determine whether the v8CTF references reflected genuine bounty research or an attempt to bypass AI safety guardrails.thehackernews+1
The first confirmed use of BlueMoon came from APT31, the China-aligned group also tracked as Violet Typhoon, on August 28. The group targeted U.S. NGOs, mining companies, and commodity traders, deploying a malicious browser extension disguised as Google Gemini that functions as a full surveillance backdoor. Within days, three additional clusters adopted the kit: UNK_LateNight targeted U.S. aerospace firms with the ShadowPad backdoor; UNK_DoubleCheck hit a Vietnamese manufacturer with a Rust-based loader; and UNK_QuietRacket went after government and financial organizations in Indonesia and Singapore.therecord+2
The shared toolkit raises questions about whether these groups draw from a common procurement pipeline or "digital quartermaster" model, according to The Record.therecord
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, giving federal agencies until September 18 to apply updates. However, Proofpoint warned that updating the browser closes the entry point but does not remove malware already installed. The GemStone extension and scheduled tasks created by other groups survive a patch, meaning previously targeted organizations should audit their systems for indicators of compromise.thehackernews+1
"A fully weaponized Chrome exploit chain has historically been a high-value, rare capability," Proofpoint said. "This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development."thehackernews