
Researchers at Proofpoint identified BlueMoon, an exploit kit being used by at least four hacking groups with suspected ties to Chinese government entities. The kit chains together three critical vulnerabilities—two in Chromium-based browsers and one in Windows kernel versions—to enable attackers to install malware on targeted systems. All three vulnerabilities received patches within 24 hours of the research being disclosed on Wednesday.
The exploit chain demonstrates an unusually aggressive and visible deployment strategy compared to typical hacking campaigns, which typically preserve newly discovered vulnerabilities by using them sparingly. Proofpoint attributed this rapid, widespread approach to two primary factors: exploitation of a “patch gap” in the Chromium supply chain, where delays occur between when patches are released by developers and when they are incorporated into public-facing browsers like Chrome and Edge, and the accelerating role of artificial intelligence in vulnerability discovery. The researchers noted that AI tools can identify security flaws faster than human-only analysis, compelling attackers to act quickly before patching opportunities close.
The exploitation chain combined two vulnerabilities in V8, Google’s JavaScript engine—a type confusion bug and a sandbox escape—to achieve remote code execution. Attackers then leveraged a local privilege escalation flaw in older Windows versions to execute malicious code with system-level permissions. The Chrome vulnerability is designated CVE-2026-85046, while the Windows flaw is tracked as CVE-2026-85880. Proofpoint characterized both V8 vulnerabilities as “patch-gap zero-days” because, while fixes existed in public source code, they remained unpatched in the latest stable releases available to end users.
The four hacking groups initiated campaigns using BlueMoon on different dates, with the first activity attributed to TA412 beginning on August 28, and the remainder starting earlier in the month. The groups targeted diverse organizations and companies across multiple sectors. Despite the high visibility of the exploit kit and the availability of patches, Proofpoint suggested BlueMoon will likely continue spreading as more actors gain access and exploit it during the rollout period of patched browser versions.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI