Four groups caught using the same Chrome and Windows exploit kit

by | Sep 17, 2026 | Technology

Four groups caught using the same Chrome and Windows exploit kit

Security researchers at Proofpoint identified an exploit kit named BlueMoon that is being deployed by at least four threat actors, including groups with alleged connections to the Chinese government. The kit chains together three separate vulnerabilities to enable attackers to install malware on compromised systems.

The BlueMoon exploit targets two vulnerabilities in Chromium-based browsers and one flaw in the Windows kernel affecting multiple versions including Windows 10, Windows Server 2019, Windows Server 2022, and Windows 11. All three vulnerabilities received patches within 24 hours of the Proofpoint announcement on Wednesday. The attacks demonstrated less sophistication in terms of stealth compared to typical campaigns, with researchers noting that attackers typically limit use of newly discovered vulnerabilities to extend their operational lifespan.

Proofpoint attributed the widespread and visible deployment pattern to two primary factors. The first involves a “patch gap” in the Chromium supply chain, the interval between when developers release patches and when those patches are integrated into browsers such as Chrome and Edge. The second factor centers on artificial intelligence capabilities that can identify vulnerabilities more rapidly than human-driven discovery methods. These conditions reportedly pressured attackers to move quickly before the exploitation window closed.

The specific Chrome vulnerabilities resided in V8, Google’s JavaScript engine, and involved a type confusion bug and a sandbox escape vulnerability. The attackers chained these exploits to achieve remote code execution, then leveraged the Windows kernel vulnerability for local privilege escalation to obtain system-level access. The first V8 vulnerability carries the designation CVE-2026-85046, while the Windows vulnerability is tracked as CVE-2026-85880.

Proofpoint researchers cautioned that despite patches being available and the kit leaving detectable traces, BlueMoon will likely see increased adoption among both espionage-motivated and financially motivated threat actors as patched versions gradually roll out across Chromium-based browsers worldwide. The ease with which the kit can be adopted and deployed suggests broader proliferation remains a concern.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI