Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

BlueMoon exploit kit targeted Windows and Chrome zero-days

Multiple cyber-espionage groups used an exploit kit called BlueMoon to target zero-day vulnerabilities in Microsoft Windows and Google Chrome.

The kit chains two security issues in Chromium-based browsers, enabling remote code execution and sandbox escape, with a Windows kernel local privilege-escalation flaw. BlueMoon runs the exploit inside a Web Worker and retries it up to five times. It fingerprints the system, elevates the Chrome renderer, then injects code into Chrome’s parent process to run an operator-selected command. Its default command uses curl to save and run an executable, typically a malware loader, under %TEMP%.

Proofpoint observed BlueMoon in spearphishing operations since August 28 and attributed them to JungleBamboo, also known as APT31, Violet Typhoon, or Tide Castle. Volexity observed similar activity on September 1 in campaigns by UTA0560 targeting customers at multiple non-governmental organizations. Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day and suspects it may have been used since 2025.

The reports identify four activity clusters, three described as Chinese or China-aligned. They include operations targeting NGOs, mining companies, U.S. aerospace and defense-industrial-base companies, and Vietnamese manufacturing firms. Payloads included Longtale/GemStone, Grimwedge, ShadowPad, and an in-memory Rust loader.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.