Skip to main content

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

0
High
Published: 09/12/2026 (09/12/2026, 11:10:00 UTC)
Source: SecurityWeek

Description

The BlueMoon exploit kit chains together three zero-day vulnerabilities—two in Chrome's V8 engine and one in Windows ALPC—to achieve sandbox escape and privilege escalation. Initially used by the China-linked APT Violet Typhoon, it has rapidly proliferated among multiple espionage-motivated threat actors targeting NGOs, aerospace, manufacturing, government, consulting, and financial sectors across the US and Southeast Asia. The vulnerabilities in Chrome were patched on September 3 and 8, 2026, and the Windows privilege escalation was fixed in the September 2026 Patch Tuesday update. BlueMoon's rapid adoption and sharing among threat actors may reflect lowered barriers to exploit development, potentially aided by AI. The exploit kit downloads and executes payloads after successful exploitation.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 11:17:16 UTC

Technical Analysis

BlueMoon is an exploit kit that chains three zero-day vulnerabilities: CVE-2026-85046 and CVE-2026-87491, both Chrome V8 engine flaws patched on September 3 and 8, 2026, and CVE-2026-85880, a Windows ALPC privilege escalation fixed in the September 2026 Patch Tuesday. The kit uses the Chrome V8 flaws to escape the sandbox, fingerprints the host, then executes the Windows privilege escalation to gain higher privileges. It injects a CreateProcess stub into the Chrome broker process to download and execute a payload. Initially deployed by the China-linked APT Violet Typhoon against US NGOs and commodity firms, it quickly spread to other Chinese espionage groups and targets in the US, Vietnam, Indonesia, and Singapore. Proofpoint notes the exploit kit's rapid development and sharing may be facilitated by AI, though no conclusive evidence confirms this. Multiple packaging variants share the same exploit chain and orchestration.

Potential Impact

Successful exploitation allows attackers to escape the Chrome sandbox and escalate privileges on Windows systems, enabling execution of arbitrary code with elevated rights. This facilitates deployment of additional payloads, potentially leading to espionage activities against targeted organizations in critical sectors such as government, aerospace, manufacturing, and finance. The exploit kit's use of zero-day vulnerabilities means targets were exposed before patches were available, increasing risk during that window. The rapid proliferation among multiple espionage groups increases the threat landscape and potential victim pool.

Defensive Guidance

All three vulnerabilities exploited by BlueMoon have been officially patched: the two Chrome V8 zero-days were fixed on September 3 and 8, 2026, and the Windows ALPC privilege escalation was patched in the September 2026 Patch Tuesday. Organizations should ensure timely application of these updates to Chrome and Windows systems. Since this is not a cloud service, remediation depends on patching affected endpoints. No additional mitigation actions are specified by the vendor advisory. Given the patches are available, applying them promptly effectively mitigates the threat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days/","fetched":true,"fetchedAt":"2026-09-12T11:17:07.217Z","wordCount":1072}

Threat ID: 6aa534b355bf5e2cf534fd56

Added to database: 09/12/2026, 11:17:07 UTC

Last enriched: 09/12/2026, 11:17:16 UTC

Last updated: 09/13/2026, 03:03:59 UTC

Views: 29

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses