Security firm Proofpoint reported Wednesday that at least four hacking groups are actively using a nearly identical exploit kit it calls BlueMoon. Some of the groups have ties to the Chinese government. The kit chains three vulnerabilities: two in Chromium-based browsers and one in the Windows kernel. Affected Windows versions include Windows 10 (October 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial Windows 11 release. All three vulnerabilities received patches in the past 24 hours.
Both browser bugs sit in V8, Google's open source JavaScript engine. A type confusion flaw and a separate sandbox escape allow remote code execution. The first V8 bug is tracked as CVE-2026-85046; Google does not assign CVEs to V8 sandbox escapes. Attackers then used a local privilege escalation, CVE-2026-85880, in older Windows versions to gain system rights. Proofpoint says both V8 flaws were patch-gap zero-days: already fixed in public upstream Chromium code, but unpatched in stable Chrome releases. The kit's developer likely reverse engineered the public patches before downstream browsers shipped fixes.
The four identified groups and their targets: TA412, a China-aligned actor indicted by the US in 2024 on behalf of China's civilian foreign intelligence agency, hit NGOs, mining companies, and commodity trading firms in the US. UNK_LateNight, a second China-aligned espionage group, targeted US aerospace companies. UNK_DoubleCheck went after a Vietnamese manufacturer. UNK_QuietRacket operated in Singapore and Indonesia. TA412 struck first, starting August 28; the other campaigns began this month. Proofpoint does not know whether additional groups have the kit.
The campaigns were unusually loud for zero-day operations, which are normally used sparingly. Proofpoint attributes the rush to the Chromium patch gap and to AI-assisted vulnerability discovery and exploit development, which lowers the cost of weaponizing open source codebases. The researchers warn BlueMoon is likely to spread further among espionage and financially motivated actors even after patches roll out fully.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.