
Security researchers from Proofpoint identified an exploit kit named BlueMoon being actively deployed by at least four separate hacking groups, several of which maintain connections to Chinese government entities. The toolkit chains three vulnerabilities together—two affecting Chromium-based browsers and one targeting Windows systems—allowing attackers to install malware of their selection on compromised devices.
The vulnerabilities targeted by BlueMoon include two flaws in V8, Google’s open source JavaScript engine, tracked as CVE-2026-85046 and an unnamed sandbox escape, along with a Windows kernel vulnerability designated CVE-2026-85880. The affected Windows versions include Windows 10 (Oct. 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities received patches within the past 24 hours from their respective vendors.
Researchers noted that the widespread and visible nature of the BlueMoon campaign departed from typical hacking tactics, which typically involve sparing use of newly discovered vulnerabilities to extend their operational window. Proofpoint attributed this aggressive deployment strategy to a combination of factors, including the existence of a “patch gap” in the Chromium supply chain—the interval between when vendors release patches and when those patches are incorporated into consumer browsers like Chrome and Edge. Additionally, the firm suggested that artificial intelligence-assisted vulnerability discovery may have accelerated the development and deployment timeline, as AI tools can identify security flaws faster than human researchers alone.
The initial attacks attributed to group TA412 commenced on August 28, with additional campaigns from other groups beginning earlier in the month. The four groups targeted diverse organizations across multiple sectors, though specific victim details were not disclosed. Proofpoint indicated that both Chromium vulnerabilities were functioning as “patch-gap zero-days” during observed activity—meaning they had been patched in public upstream Chromium source code but remained unpatched in the latest stable releases available to the public.
Despite the rapid patching of all three vulnerabilities, Proofpoint cautioned that BlueMoon may continue circulating due to its relative ease of adoption and deployment. The researchers predicted the toolkit could proliferate further among both espionage-focused and financially motivated threat actors as patched browser versions roll out across Chromium-based platforms.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI