BlueMoon exploit kit spreads to four hacking groups within days

NewsFri, 11 Sep 2026 14:24:29 UTC5 hours ago
BlueMoon exploit kit spreads to four hacking groups within days

A single piece of attack code, quietly built to chain three unpatched flaws in Chrome and Windows, has ended up in the hands of at least four separate hacking crews within days of each other. Researchers at cybersecurity firm Proofpoint have named it BlueMoon exploit kit, and they say it’s already been used against US nonprofits, aerospace contractors, a Vietnamese manufacturer, and organizations across Singapore and Indonesia — a spread pattern that suggests the tool moved from a single developer to multiple threat groups almost immediately after it was built.

Key takeaways

  • Proofpoint identified the BlueMoon exploit kit being used by at least four hacking groups, some linked to Chinese state interests, starting around August 28.
  • The kit chains two Chromium V8 flaws with a Windows kernel privilege escalation bug to install malware of the attacker’s choosing.
  • All three vulnerabilities — tracked as CVE-2026-85046, a Chromium V8 sandbox escape, and CVE-2026-85880 — received patches within roughly 24 hours of the disclosure.
  • Targets span US NGOs, mining and aerospace firms, a Vietnamese manufacturer, and entities in Singapore and Indonesia.
  • The attacks exploited a “patch gap” between Chromium’s public source fixes and their rollout into Chrome and Edge, a gap researchers say AI-assisted analysis may have helped attackers close faster.

Active Use of BlueMoon Exploit Kit by Multiple Hacking Groups

At least four distinct hacking groups deployed a nearly identical version of the BlueMoon exploit kit, according to Proofpoint, with some of those groups tied to Beijing’s intelligence apparatus. That’s an unusually crowded field for a single exploit chain — fully weaponized Chrome attacks have historically stayed in the hands of one or two well-resourced operators, not four at once.

… Continue reading the full article at the original source below.

Read from Source · en.cryptonomist.ch ↗
This content is automatically aggregated. Full credit goes to the original publisher (en.cryptonomist.ch).

Related