Four Spy Groups Deployed BlueMoon Within 7 Days to Exploit Chrome and Windows
Updated
Updated · The Hacker News · Sep 9
Four Spy Groups Deployed BlueMoon Within 7 Days to Exploit Chrome and Windows
3 articles · Updated · The Hacker News · Sep 9
Summary
Proofpoint said four espionage clusters used the previously undocumented BlueMoon exploit kit between Aug. 28 and Sept. 3, with APT31 first seen deploying it and three more groups following within days.
Three vulnerabilities powered the chain: Chrome bug CVE-2026-85046, an unassigned V8 sandbox escape, and Windows ALPC flaw CVE-2026-85880, letting attackers move from phishing links to code execution, sandbox escape and privilege escalation.
APT31 targeted U.S. NGOs, mining and commodity firms, while other clusters hit U.S. aerospace, a Vietnamese manufacturer, and government, consulting and financial organizations in Indonesia and Singapore.
Google patched CVE-2026-85046 last week and Microsoft fixed CVE-2026-85880 in September Patch Tuesday, but Proofpoint warned patches do not remove payloads already installed, including the GemStone extension and persistence tasks.
CISA added the Chrome flaw to its exploited-vulnerabilities catalog on Sept. 4 and gave U.S. civilian agencies until Sept. 18 to patch, as researchers warned BlueMoon could spread beyond China-linked espionage actors.
Does the simultaneous deployment of BlueMoon across distinct espionage groups point to a hidden, centralized exploit quartermaster?
If AI helped build the BlueMoon exploit, could the verbose code comments be a deliberate false flag to mislead threat hunters?
How can organizations protect themselves when the delay between open-source fixes and stable browser releases creates an unpreventable exploitation window?
The 2026 BlueMoon Campaign: AI-Accelerated Patch-Gap Exploitation and the Rapid Spread of State-Sponsored Chrome Attacks
Overview
The BlueMoon campaign in August–September 2026 exposed a critical weakness in open-source software: security fixes for Chromium were made public before browser vendors could distribute updates, creating a 'patch-gap' window. Threat actors used AI-assisted tools to quickly analyze these public patches and build powerful exploit chains, targeting outdated browsers and older Windows systems. By prioritizing speed over stealth, attackers deployed malicious browser extensions that survived updates and evaded detection. Multiple state-aligned groups rapidly adopted the same exploit kit, enabled by a centralized distribution model, forcing urgent patching and advanced threat hunting across U.S. organizations to contain the threat.