GemStone is a malicious Chromium browser extension that provides browser-surveillance and credential-theft backdoor functionality on Windows systems. It masquerades as an AI-powered Google Gemini browsing companion and has been deployed by the China-aligned espionage actor TA412, also known as APT31 and Violet Typhoon.
GemStone collects keystrokes, cookies, session data, browser storage, browsing activity, and screenshots. Operators can inject a keylogger into browser tabs, monitor pages for specified keywords, trigger additional collection, and issue arbitrary HTTP requests from the extension context. A background service worker supports collection, command polling, and exfiltration through command-and-control infrastructure hosted on Cloudflare Workers.
TA412 delivered GemStone through spearphishing campaigns targeting U.S. nongovernmental organizations, mining companies, and physical commodity-trading firms. Lures impersonated university students seeking internships or used academic-conference outreach, sometimes establishing rapport before sending malicious links. These links led to websites hosting the BlueMoon exploit kit, which exploited Chromium and Windows vulnerabilities to execute an installer outside the browser sandbox. The installer deployed GemStone by modifying browser preferences and bypassing extension-integrity protections, registering the extension for persistent operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The first exploit targets CVE-2026-85046 in V8's optimizing compilers. When an array's element type changes during sorting, the optimized code can treat a value as the wrong type.
That DLL checks the Windows build again, then tries CVE-2026-85880. The exploit uses the ALPC communication and WNF notification mechanisms to gain kernel read/write access.
The next exploit, CVE-2026-87491, escapes the V8 sandbox. BlueMoon corrupts WebAssembly metadata and replaces compiled function code with the p1 shellcode.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA412's msgbox.exe installer extracts GemStone to C:\Users\Public\stomp_ext and registers it through modified browser preferences.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
TA412 used spearphishing lures posing as university interns and academic conference outreach... UNK_LateNight targeted US aerospace companies with defense-themed procurement lures... UNK_QuietRacket targeted government and financial organizations... using conference-themed phishing.
GemStone est une extension Chromium malveillante destinée au vol de credentials et à la surveillance du navigateur.
“This browser extension, which Proofpoint tracks as GemStone, allowed the Beijing spies to issue commands through a command-and-control (C&C) channel.”
The extension is a browser-surveillance and credential-theft backdoor dubbed GemStone that allows the threat actor to issue commands through a command-and-control (C2) channel. The rogue DLL communicates with Cloudflare Workers domains.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware delivered through BlueMoon in espionage-focused campaigns. The content does not describe its specific functionality.
A malicious browser extension delivered through BlueMoon in TA412 campaigns. It masquerades as a Gemini browsing companion and is installed through modified browser preferences. Its background.js service worker collects keystrokes, cookies, browser storage, and screenshots, and uses a worker-hosted command-and-control server to receive commands and upload stolen data.
Malicious Chromium extension used for credential theft and browser surveillance.
A malicious Chromium extension deployed by TA412 that steals cookies, browser storage, session data, keystrokes, navigation data, and screenshots. Operators can initiate further collection, inject its keylogger into browser tabs, monitor specified keywords, and make arbitrary HTTP requests from the extension context.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.