BlueMoon is a browser exploitation toolkit first observed on August 28, 2026, targeting Chromium-based browsers on Windows. It chains two Chromium V8 vulnerabilities with a Windows kernel privilege-escalation vulnerability to achieve browser code execution, escape sandbox restrictions, and execute attacker-selected payloads with elevated privileges. The chain includes V8 type-confusion vulnerability CVE-2026-85046 and Windows Advanced Local Procedure Call vulnerability CVE-2026-85880. Its browser exploits were used during a patch gap, when upstream Chromium fixes were publicly available but had not yet reached stable browser releases.
BlueMoon fingerprints compromised hosts to assess compatibility with its privilege-escalation component, reflectively loads a reconnaissance DLL, and injects shellcode into the parent Chrome broker process to execute an operator-specified command. Its default execution mechanism uses curl to download and launch an executable. Campaigns typically begin with spearphishing links leading to attacker-controlled exploit pages; some pages subsequently redirect visitors to legitimate websites while exploitation proceeds in the background.
BlueMoon has been used by multiple espionage-focused threat clusters, including China-linked TA412, also known as APT31, JungleBamboo, and Violet Typhoon, alongside UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket. Observed targets include U.S. nonprofit, mining, commodity-trading, aerospace, and defense organizations; a Vietnamese manufacturer; and government, consulting, and financial organizations in Indonesia and Singapore. Operators have used the kit to deliver distinct payloads, including the GemStone malicious browser extension, ShadowPad, Rust-based loaders, and custom staged malware. Credential theft, surveillance, and persistence depend on these subsequent payloads rather than being inherent capabilities of the exploit kit.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BlueMoon Exploit Kit, first observed on August 28, 2026, turns visits to malicious websites into Windows malware execution.
BlueMoon Exploit Kit, first observed on August 28, 2026, turns visits to malicious websites into Windows malware execution.
BlueMoon Exploit Kit, first observed on August 28, 2026, turns visits to malicious websites into Windows malware execution.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These groups utilized the same exploit kit, identified as BlueMoon by cybersecurity firm Proofpoint, to compromise Chrome browsers.
These groups utilized the same exploit kit, identified as BlueMoon by cybersecurity firm Proofpoint, to compromise Chrome browsers.
These groups utilized the same exploit kit, identified as BlueMoon by cybersecurity firm Proofpoint, to compromise Chrome browsers.
These groups utilized the same exploit kit, identified as BlueMoon by cybersecurity firm Proofpoint, to compromise Chrome browsers.
The hidden iframe loaded a config.html element said to have used the same BlueMoon exploit kit combining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880.
BlueMoon est un exploit kit chaînant trois vulnérabilités pour compromettre des systèmes Windows via le navigateur.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The spoofed websites loaded an additional HTML element via a hidden iframe; "config.html" used the BlueMoon exploit kit to deliver the Chrome-Windows exploit chain.
BlueMoon utilise curl pour télécharger puis exécuter un payload depuis le répertoire %TEMP%.
99 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivery kit used in espionage campaigns targeting the US and Southeast Asia. Spearphishing directs victims to attacker-controlled websites, where the kit chains Chrome V8 exploitation, sandbox escape, and Windows kernel privilege escalation to execute payloads outside the browser sandbox. Delivered payloads include GemStone, ShadowPad, an unnamed Rust loader, and custom .NET-staged malware.
BlueMoon is an exploit kit used in this campaign to chain two Google Chrome vulnerabilities with a Windows Advanced Local Procedure Call vulnerability, escape the browser sandbox, and deliver the CLEANGULP payload.
Exploit kit for Windows browser compromise that chains two Chromium V8 vulnerabilities and a Windows kernel local-privilege-escalation vulnerability. After exploitation, it reflectively loads a DLL to fingerprint the host and elevate privileges, then uses curl to download and execute a payload from %TEMP%.
A browser exploit kit that chains CVE-2026-85046 and CVE-2026-87491 in Chromium V8 for browser exploitation and sandbox escape, then CVE-2026-85880 for Windows kernel privilege escalation. It fingerprints hosts, reflectively loads a DLL, injects shellcode into the Chrome broker process, and by default uses curl to download and execute an operator-specified payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.