Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
Security researchers at Proofpoint have identified a new exploit kit, dubbed BlueMoon, that chains flaws in Chromium-based browsers and Microsoft Windows to compromise organisations' networks. At least four espionage-linked groups, most with suspected ties to China, have used the kit since late August, targeting fewer than 20 known organisations across the US and Southeast Asia, though researchers believe the true number affected is likely higher. The rapid development and sharing of the kit among multiple threat actors within days is being cited as a sign that AI-assisted exploit development is lowering the barrier to entry for this once-rare, high-value capability.
BlueMoon combines three vulnerabilities: a V8 type confusion flaw (CVE-2026-85046) enabling remote code execution, a Chrome V8 sandbox escape with no assigned CVE, and a Windows privilege escalation bug (CVE-2026-85880) in Advanced Local Procedure Call. Its first confirmed use, on 28 August, involved Chinese state-linked group TA412 (also known as Violet Typhoon or APT31) targeting NGOs, mining firms and commodity traders in the US. Both browser flaws were "patch-gap" zero-days, fixed in upstream Chromium code on 7 August but left unpatched in public stable releases for weeks, giving attackers a window to exploit them before Google and Microsoft issued fixes in early September; Microsoft patched the Windows flaw on 9 September.
- New BlueMoon exploit kit chains Chrome and Windows flaws
- Used by China-linked espionage groups against US, Asia targets
- Highlights "patch-gap" zero-days and AI-driven exploit development risks