BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
The BlueMoon exploit kit chains together three zero-day vulnerabilities—two in Chrome's V8 engine and one in Windows ALPC—to achieve sandbox escape and privilege escalation. Initially used by the China-linked APT Violet Typhoon, it has rapidly proliferated among multiple espionage-motivated threat actors targeting NGOs, aerospace, manufacturing, government, consulting, and financial sectors across the US and Southeast Asia. The vulnerabilities in Chrome were patched on September 3 and 8, 2026, and the Windows privilege escalation was fixed in the September 2026 Patch Tuesday update. BlueMoon's rapid adoption and sharing among threat actors may reflect lowered barriers to exploit development, potentially aided by AI. The exploit kit downloads and executes payloads after successful exploitation.
AI Analysis
Technical Summary
BlueMoon is an exploit kit that chains three zero-day vulnerabilities: CVE-2026-85046 and CVE-2026-87491, both Chrome V8 engine flaws patched on September 3 and 8, 2026, and CVE-2026-85880, a Windows ALPC privilege escalation fixed in the September 2026 Patch Tuesday. The kit uses the Chrome V8 flaws to escape the sandbox, fingerprints the host, then executes the Windows privilege escalation to gain higher privileges. It injects a CreateProcess stub into the Chrome broker process to download and execute a payload. Initially deployed by the China-linked APT Violet Typhoon against US NGOs and commodity firms, it quickly spread to other Chinese espionage groups and targets in the US, Vietnam, Indonesia, and Singapore. Proofpoint notes the exploit kit's rapid development and sharing may be facilitated by AI, though no conclusive evidence confirms this. Multiple packaging variants share the same exploit chain and orchestration.
Potential Impact
Successful exploitation allows attackers to escape the Chrome sandbox and escalate privileges on Windows systems, enabling execution of arbitrary code with elevated rights. This facilitates deployment of additional payloads, potentially leading to espionage activities against targeted organizations in critical sectors such as government, aerospace, manufacturing, and finance. The exploit kit's use of zero-day vulnerabilities means targets were exposed before patches were available, increasing risk during that window. The rapid proliferation among multiple espionage groups increases the threat landscape and potential victim pool.
Mitigation Recommendations
All three vulnerabilities exploited by BlueMoon have been officially patched: the two Chrome V8 zero-days were fixed on September 3 and 8, 2026, and the Windows ALPC privilege escalation was patched in the September 2026 Patch Tuesday. Organizations should ensure timely application of these updates to Chrome and Windows systems. Since this is not a cloud service, remediation depends on patching affected endpoints. No additional mitigation actions are specified by the vendor advisory. Given the patches are available, applying them promptly effectively mitigates the threat.
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Description
The BlueMoon exploit kit chains together three zero-day vulnerabilities—two in Chrome's V8 engine and one in Windows ALPC—to achieve sandbox escape and privilege escalation. Initially used by the China-linked APT Violet Typhoon, it has rapidly proliferated among multiple espionage-motivated threat actors targeting NGOs, aerospace, manufacturing, government, consulting, and financial sectors across the US and Southeast Asia. The vulnerabilities in Chrome were patched on September 3 and 8, 2026, and the Windows privilege escalation was fixed in the September 2026 Patch Tuesday update. BlueMoon's rapid adoption and sharing among threat actors may reflect lowered barriers to exploit development, potentially aided by AI. The exploit kit downloads and executes payloads after successful exploitation.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
BlueMoon is an exploit kit that chains three zero-day vulnerabilities: CVE-2026-85046 and CVE-2026-87491, both Chrome V8 engine flaws patched on September 3 and 8, 2026, and CVE-2026-85880, a Windows ALPC privilege escalation fixed in the September 2026 Patch Tuesday. The kit uses the Chrome V8 flaws to escape the sandbox, fingerprints the host, then executes the Windows privilege escalation to gain higher privileges. It injects a CreateProcess stub into the Chrome broker process to download and execute a payload. Initially deployed by the China-linked APT Violet Typhoon against US NGOs and commodity firms, it quickly spread to other Chinese espionage groups and targets in the US, Vietnam, Indonesia, and Singapore. Proofpoint notes the exploit kit's rapid development and sharing may be facilitated by AI, though no conclusive evidence confirms this. Multiple packaging variants share the same exploit chain and orchestration.
Potential Impact
Successful exploitation allows attackers to escape the Chrome sandbox and escalate privileges on Windows systems, enabling execution of arbitrary code with elevated rights. This facilitates deployment of additional payloads, potentially leading to espionage activities against targeted organizations in critical sectors such as government, aerospace, manufacturing, and finance. The exploit kit's use of zero-day vulnerabilities means targets were exposed before patches were available, increasing risk during that window. The rapid proliferation among multiple espionage groups increases the threat landscape and potential victim pool.
Defensive Guidance
All three vulnerabilities exploited by BlueMoon have been officially patched: the two Chrome V8 zero-days were fixed on September 3 and 8, 2026, and the Windows ALPC privilege escalation was patched in the September 2026 Patch Tuesday. Organizations should ensure timely application of these updates to Chrome and Windows systems. Since this is not a cloud service, remediation depends on patching affected endpoints. No additional mitigation actions are specified by the vendor advisory. Given the patches are available, applying them promptly effectively mitigates the threat.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days/","fetched":true,"fetchedAt":"2026-09-12T11:17:07.217Z","wordCount":1072}
Threat ID: 6aa534b355bf5e2cf534fd56
Added to database: 09/12/2026, 11:17:07 UTC
Last enriched: 09/12/2026, 11:17:16 UTC
Last updated: 09/13/2026, 03:03:59 UTC
Views: 29
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.