Multiple cyber-espionage groups used an exploit kit called BlueMoon to target zero-day vulnerabilities in Microsoft Windows and Google Chrome.
The kit chains two security issues in Chromium-based browsers, enabling remote code execution and sandbox escape, with a Windows kernel local privilege-escalation flaw. BlueMoon runs the exploit inside a Web Worker and retries it up to five times. It fingerprints the system, elevates the Chrome renderer, then injects code into Chrome’s parent process to run an operator-selected command. Its default command uses curl to save and run an executable, typically a malware loader, under %TEMP%.
Proofpoint observed BlueMoon in spearphishing operations since August 28 and attributed them to JungleBamboo, also known as APT31, Violet Typhoon, or Tide Castle. Volexity observed similar activity on September 1 in campaigns by UTA0560 targeting customers at multiple non-governmental organizations. Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day and suspects it may have been used since 2025.
The reports identify four activity clusters, three described as Chinese or China-aligned. They include operations targeting NGOs, mining companies, U.S. aerospace and defense-industrial-base companies, and Vietnamese manufacturing firms. Payloads included Longtale/GemStone, Grimwedge, ShadowPad, and an in-memory Rust loader.
Comments
0No comments yet. Be the first to comment.