Overview
- Proofpoint says the first in‑the‑wild use of BlueMoon was by the China‑linked group TA412 on August 28, and researchers observed follow‑on activity from at least three other espionage clusters in early September.
- BlueMoon chains two V8 (Chromium) browser flaws with a Windows local privilege‑escalation bug, specifically CVE‑2026‑85046, CVE‑2026‑87491, and CVE‑2026‑85880, to break out of the browser sandbox and gain system privileges.
- The exploit kit includes verbose logs, handover documents and detailed comments that analysts say are consistent with rapid, possibly AI‑assisted development and with defaults that favor quick payload delivery over stealth.
- Google rolled the Chromium/V8 fixes into Chrome stable on September 3 and Microsoft patched CVE‑2026‑85880 in September Patch Tuesday, and defenders are urged to apply those updates and hunt for GemStone and ShadowPad artifacts.
- Observed campaigns used phishing lures to install a browser surveillance extension called GemStone or to drop backdoors via DLL sideloading, researchers warn the true number of victims is likely far higher and that the kit lowers the barrier for broader abuse.