At least four separate espionage-motivated threat groups, most with suspected links to Chinese state intelligence, deployed a previously undocumented exploit kit within the same week to break into government, defense, NGO and financial-sector targets across the United States and Southeast Asia, according to research published by security firm Proofpoint.
Chaining a Patch Gap Into a Working Exploit
Proofpoint named the kit BlueMoon, describing it as a chain combining two zero-day flaws in Chromium-based browsers with a Microsoft Windows privilege-escalation bug, letting an attacker escape Chrome’s V8 sandbox and gain elevated access on a victim’s machine. The underlying Chrome flaw, CVE-2026-85046, was fixed in Chromium’s source code on August 7 but did not reach the stable Chrome release until September 3, nearly four weeks later; researchers say that gap between the public fix and the downstream browser update gave attackers a window to reverse-engineer the patch and build a working exploit before most users were protected. The companion Windows flaw, CVE-2026-85880, was addressed as part of Microsoft’s September 2026 Patch Tuesday updates.
Four Campaigns, Multiple Payloads, One Shared Toolkit
The first confirmed use came from TA412, a China-nexus group also tracked as APT31 or Violet Typhoon, which began targeting US NGOs, mining companies and physical commodity trading firms on August 28 using phishing emails posing as university outreach. Proofpoint identified three additional clusters using the same kit in the following days, including a group tracked as UNK_DoubleCheck that targeted a Vietnamese manufacturing firm from a compromised Southeast Asian government email account, and UNK_QuietRacket, which used lures referencing Indonesian conferences to target government, consulting and financial organizations in Indonesia and Singapore. Payloads delivered through the kit included the GemStone and ShadowPad malware families.
Patching Alone Does Not Remove Existing Footholds
CISA added the exploited Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, giving US federal civilian agencies until September 18 to patch. Researchers caution that updating the browser closes the initial infection route but does not remove malicious components, such as the GemStone extension or scheduled tasks, that earlier-compromised systems may already be running, meaning organizations that may have been targeted need to actively check for signs of persistence rather than relying on patching alone.

Leave a Reply