Overview
- Proofpoint found a previously undocumented exploit kit named BlueMoon that chains two V8/Chromium bugs and a Windows ALPC local privilege escalation to move from browser code execution to full system compromise.
- The first known use was by the China‑aligned group TA412 on Aug. 28, and within days at least three other espionage clusters adopted variants that modified payloads and targeting.
- The chain exploits CVE-2026-85046 and CVE-2026-87491 in Chrome’s V8 JavaScript engine to escape the browser sandbox, then uses CVE-2026-85880 to elevate privileges on older Windows builds and run commands as a higher‑privileged process.
- Google, Microsoft, and other vendors have released patches and CISA added the three CVEs to its Known Exploited Vulnerabilities catalog, but installed backdoors such as malicious browser extensions, DLL sideloading and scheduled tasks survive updates and require active detection and removal.
- Proofpoint and vendor teams published indicators and detection rules and warned the kit’s fast, noisy sharing and verbose tooling suggest easier reuse and possible AI‑assisted development, increasing the risk of wider proliferation to other actors.