Four Groups Used Same BlueMoon Chrome Exploit Kit Within a Week, Proofpoint Says
Proofpoint: four groups, including China-aligned TA412, used BlueMoon Chrome exploit kit in a week; flaws patched.
Proofpoint said BlueMoon was first observed on August 28, 2026, in use by a threat actor tracked as TA412, also known as Violet Typhoon. The group, which has previously targeted businesses using Microsoft SharePoint, used the kit to repeatedly target a small number of non-governmental organizations, mining companies, and physical commodity trading firms in the United States.
Soon after, three more groups were seen using BlueMoon. UNK_LateNight, another China-aligned espionage group, targeted multiple U.S. aerospace companies. UNK_DoubleCheck targeted a Vietnamese manufacturing entity. UNK_QuietRacket attacked organizations across Singapore and Indonesia. Proofpoint noted that the groups did not try particularly hard to hide their activity, an unusual approach because stealth normally helps attackers exploit a vulnerability for longer.
The Chromium flaws were in V8, the JavaScript engine used by Chromium-based browsers. The first was a type confusion bug tracked as CVE-2026-85046 and rated 8.8 out of 10, or high severity. The second was a sandbox escape flaw for which Google did not assign a CVE or a severity score. The Windows bug, tracked as CVE-2026-85880, was rated 7.8 out of 10, or high severity. Proofpoint described it as a heap-based buffer overflow in Windows Advanced Local Procedure Call that allows an attacker who can already execute code inside a low-privilege AppContainer to escape the sandbox and elevate privileges to SYSTEM. No additional user interaction is required. The Windows flaw affected older versions including Windows 10 October 2018 Update, Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11.
Proofpoint offered an explanation for why the attackers chose speed over stealth. It said there is a very short window between Google patching a Chromium vulnerability and that fix being deployed to browsers such as Edge or Brave. During that window, attackers can study how Google fixed the flaw, reverse-engineer it, and deploy an exploit before the browser is patched, leaving no time to hide.
"Both V8 vulnerabilities were 'patch-gap' zero-days at the time of the observed activity," Proofpoint said. "In other words, while they were known vulnerabilities already fixed in public upstream Chromium source code, they remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public. It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain."
Proofpoint also pointed to artificial intelligence as a factor. It said AI appears to have made flaw detection significantly faster, reducing the barrier to entry and encouraging threat actors to move more loudly. "A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals," Proofpoint said. "This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development."
All three flaws have been patched. The report advised users to run the latest version of their operating system and Chromium-based browser.
Editor's Summary
Proofpoint detailed BlueMoon, an exploit kit that combined two Chromium flaws and one Windows bug and was used by four threat groups, including China-aligned TA412, within a week in late August 2026. The groups targeted NGOs, aerospace, manufacturing, and organizations in the United States and Asia. All three vulnerabilities have been patched, but the rapid, shared use of the kit points to a lower barrier for deploying browser exploit chains.