Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Sino-Centric Exploit Kit Emerge: The Rise of BlueMoon and the Growing Threat of State-Sponsored Cyber Espionage




Four distinct spy groups have employed the same Chrome and Windows exploit kit, BlueMoon, within a span of just one week, according to a recent report by Proofpoint. This revelation highlights the growing sophistication and coordination of state-sponsored cyber espionage efforts, as well as the increasing ease with which threat actors can acquire and deploy advanced exploit kits. The BlueMoon exploit kit is believed to have been used by China-aligned state-sponsored groups, and its emergence has sent shockwaves through the cybersecurity community. To stay ahead of this growing threat, organizations must remain vigilant and proactive in their cybersecurity efforts.

  • Four distinct spy groups have used the same Chrome and Windows exploit kit, BlueMoon, within a week.
  • BlueMoon chains together multiple vulnerabilities in Microsoft Windows and Google Chrome to achieve malicious goals.
  • The first in-the-wild use of BlueMoon was attributed to a China-aligned state-sponsored group, APT31, on August 28, 2026.
  • Several other espionage-motivated clusters have used BlueMoon, with some suspected China nexus, but some usage remains unattributed.
  • The BlueMoon exploit chain employs three vulnerabilities, including a V8 sandbox escape and a heap-based buffer overflow vulnerability in Windows.
  • The exploit kit is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors.



  • In a recent development that has sent shockwaves through the cybersecurity community, it has been reported that four distinct spy groups have employed the same Chrome and Windows exploit kit within a span of just one week. This revelation highlights the growing sophistication and coordination of state-sponsored cyber espionage efforts, as well as the increasing ease with which threat actors can acquire and deploy advanced exploit kits.

    According to a report published by Proofpoint, a renowned cybersecurity firm, the exploit kit in question is called BlueMoon, and it chains together multiple vulnerabilities in Microsoft Windows and Google Chrome to achieve its malicious goals. The first in-the-wild use of BlueMoon was attributed to the China-aligned state-sponsored group tracked as APT31 (also known as Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon), which began using the exploit kit on August 28, 2026.

    Within days of this initial deployment, several other espionage-motivated clusters began using BlueMoon, with the majority of these clusters having a suspected China nexus. However, it is worth noting that some usage of BlueMoon remains unattributed, and there are indications that potentially more actors may be using the exploit kit.

    The BlueMoon exploit chain employs three vulnerabilities: CVE-2026-85046, a type confusion in V8 in Google Chrome; a V8 sandbox escape that does not have an assigned CVE identifier; and CVE-2026-85880, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC). Interestingly, both V8 vulnerabilities in Chrome are said to have been "patch-gap" zero-days at the time they were maliciously exploited.

    The enterprise security company, Proofpoint, stated that the flaws had already been fixed in public upstream Chromium source code, but were yet to be propagated to the latest stable releases of Chrome and Chromium-based browsers available. It is suspected that the developer behind the exploit kit may have been closely keeping track of publicly available Chromium patches to put together the browser exploit chain.

    Attack chains making use of BlueMoon have been found to rely on phishing emails as a starting point to trick targets into visiting an actor-controlled URL that triggers the two V8 flaws in succession to achieve code execution and escape the browser sandbox. Once inside, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit.

    The presence of extensive logging capabilities and verbose comments within the source code artifacts suggests that the malware may have been developed with assistance using artificial intelligence (AI) tools. This is also bolstered by repeated references to the v8CTF challenge, an exploit-focused vulnerability reward program (VRP) and capture-the-flag (CTF) competition run by Google targeting the V8 engine.

    Proofpoint stated that it is not known how multiple distinct threat actors obtained access to the exploit kit, but that it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers.

    The emergence of BlueMoon highlights the growing threat of state-sponsored cyber espionage and the increasing ease with which threat actors can acquire and deploy advanced exploit kits. As AI agents increasingly enable threat actor exploit development, this trend is likely to continue, making it essential for organizations to stay vigilant and proactive in their cybersecurity efforts.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Sino-Centric-Exploit-Kit-Emerge-The-Rise-of-BlueMoon-and-the-Growing-Threat-of-State-Sponsored-Cyber-Espionage-ehn.shtml

  • https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85046

  • https://www.cvedetails.com/cve/CVE-2026-85046/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85880

  • https://www.cvedetails.com/cve/CVE-2026-85880/


  • Published: Wed Sep 9 16:05:18 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us