New AI-enabled BlueMoon exploit kit targets Chrome and Windows in US and Asia
A China-linked espionage group deployed the BlueMoon exploit kit, chaining two Chromium V8 flaws and a Windows privilege-escalation bug to infiltrate fewer than 20 organizations in the US and Southeast Asia.
Proofpoint’s threat team uncovered a new exploit kit named BlueMoon, which links two V8 engine vulnerabilities in Chromium-based browsers with a Windows Advanced Local Procedure Call privilege-escalation bug (CVE-2026-85880). First observed on August 28, the kit was used by the China-linked espionage group TA412, also known as Violet Typhoon or APT31, to compromise NGOs, mining companies and commodity traders in the United States.
Within days, additional China-aligned clusters adopted the kit, targeting US aerospace firms, a Vietnamese manufacturer, and financial and government entities in Indonesia and Singapore through phishing lures. The attack chain drops a malicious browser extension called GemStone and backdoors like ShadowPad, enabling command-and-control, credential theft and keylogging. Google patched the V8 flaw (CVE-2026-85046) on September 3, while Microsoft released a fix for the Windows bug on September 2, but the incidents highlight a growing trend of AI-assisted exploit creation exploiting open-source patch-gap windows. Proofpoint warns that BlueMoon may also be leveraged by financially motivated actors, suggesting a broader shift in cyber-espionage tactics.
Why it matters
The case shows how AI can accelerate creation of high-impact exploits, raising the threat level for organizations worldwide.
In this story
Related stories
2 in this thread