Politics news and analysis from Sun Belt Post
Technology

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

At least four espionage groups, most with suspected links to China, are using a new exploit kit called BlueMoon. This kit combines two Chromium-based browser vulnerabilities (CVE-2026-85046 and a sandbox escape) and a Windows privilege escalation bug (CVE-2026…

Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

At least four espionage groups, most with suspected links to China, are using a new exploit kit called BlueMoon. This kit combines two Chromium-based browser vulnerabilities (CVE-2026-85046 and a sandbox escape) and a Windows privilege escalation bug (CVE-2026-85880) to infiltrate organizations in the US and Southeast Asia.

Mark Kelly, a threat researcher at Proofpoint, notes that the exact targets remain unknown, though fewer than 20 organizations were initially observed. The true number is likely higher. BlueMoon was first detected on August 28, when Beijing-backed group TA412 (Violet Typhoon/APT31) targeted NGOs, mining companies, and commodity traders. TA412 is linked to China’s Ministry of State Security (MSS) and was previously charged by US prosecutors for computer intrusions and wire fraud.

Within days, other espionage groups—mostly suspected to be China-aligned—also adopted BlueMoon. The exploit was developed and shared rapidly, possibly due to AI-driven capabilities enabling quicker reverse engineering of Chromium patches. Google patched CVE-2026-85046 in Chrome on September 3, while Microsoft fixed CVE-2026-85880 on Tuesday. Both vulnerabilities were zero-days at the time of exploitation, exploiting a ‘patch-gap’ where upstream Chromium fixes were available but not yet deployed in public releases.

The attack chain begins with phishing emails luring victims into clicking malicious links. This triggers remote code execution via the V8 flaws, escapes the browser sandbox, and exploits the Windows bug to download payloads—including browser-surveillance malware, credential stealers, and backdoors like GemStone (TA412) or ShadowPad (UNK_LateNight). TA412’s first campaign used internship-related lures, while UNK_LateNight targeted aerospace firms with defense-industry-specific phishing. Another group, UNK_DoubleCheck, targeted a Vietnamese manufacturing firm via a compromised Southeast Asian government email. Finally, UNK_QuietRacket exploited BlueMoon in Indonesia and Singapore, using conference-related lures like the Indo Startup Expo and WCCE 2026.

Proofpoint warns that BlueMoon’s rapid development and reliance on patch-gaps suggest this model will persist, making it accessible to both espionage and financially motivated attackers.

Source: The Register

Distributed to Politics · Sun Belt Post by RedPress.

Related News

Contact Advertise Search RSS