Regions Targeted: US, Asia
Related Threat Actors: TA412 (Violet Typhoon), UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket
Related Families: BlueMoon, GemStone, ShadowPad
Key Takeaways
What is BlueMoon Exploit Kit?
Proofpoint researchers identified multiple espionage-motivated threat actors rapidly adopting BlueMoon beginning in late August 2026. The first observed user was China-aligned TA412, also known as APT31, JungleBamboo, Violet Typhoon, and TIDE CASTLE, on August 28. Within days, several additional espionage-focused clusters began deploying the same exploit kit, with most observed activity having a suspected China nexus. Proofpoint cautioned, however, that available evidence does not establish BlueMoon as exclusive to China-aligned operators.
BlueMoon combines three vulnerabilities to progress from browser exploitation to elevated execution on Windows. The chain begins with CVE-2026-85046, a type-confusion vulnerability in Chromium’s V8 JavaScript engine, followed by CVE-2026-87491, an out-of-bounds write vulnerability in V8 that BlueMoon uses for sandbox escape. The kit then uses CVE-2026-85880, a Windows kernel local privilege escalation vulnerability affecting older Windows builds, to elevate the compromised browser renderer process.
Both V8 vulnerabilities were “patch-gap” zero-days when Proofpoint observed exploitation. Although fixes were already publicly available in upstream Chromium source code, they had not yet reached stable Chrome and other Chromium-based browser releases. The fix for CVE-2026-85046, for example, was committed on August 7 but was not incorporated into the general stable Chromium build until September 3. This created a nearly four-week window in which the code change could potentially be analyzed and weaponized before most users received a patched browser.
Following successful browser exploitation, BlueMoon reflectively loads a DLL to fingerprint the Windows host and determine whether it is compatible with the LPE stage. After privilege escalation, a separate injector shellcode reaches the parent Chrome broker process and executes an operator-specified command. BlueMoon’s default configuration uses curl to retrieve an executable, save it to the Windows %TEMP% directory, and execute it.
Multiple Espionage Actors Rapidly Adopt BlueMoon
TA412
TA412 initially deployed BlueMoon against a small number of US NGOs, mining companies, and physical commodity trading organizations. Its spearphishing campaigns used several social-engineering themes, including messages impersonating university students seeking internships and outreach related to an upcoming academic conference. In some cases, the actor first established rapport with targeted individuals before sending a malicious link. Victims who followed the link reached actor-controlled infrastructure hosting BlueMoon. The page attempted browser exploitation while displaying a loading screen and subsequently redirected the victim to a legitimate website. Successful exploitation delivered a loader that installed a malicious Chromium extension tracked by Proofpoint as GemStone.
GemStone masquerades as an “AI-powered browsing companion by Google Gemini” but functions as a browser-surveillance and credential-theft backdoor. Its capabilities include collecting cookies, browser storage, session information, keystrokes, navigation data, and screenshots. Operators can remotely trigger additional collection, inject the malware’s keylogger into browser tabs, specify keywords to monitor, and execute arbitrary HTTP requests from the browser-extension context.
UNK_LateNight
Beginning September 2, China-aligned UNK_LateNight targeted US aerospace companies using business-to-business and request-for-quotation phishing lures associated with the US defense industrial base. Successful exploitation ultimately deployed the ShadowPad backdoor, which established persistence through a scheduled task and included capabilities for Firefox profile theft and network traffic collection.
UNK_DoubleCheck
Also on September 2, UNK_DoubleCheck, an espionage-motivated cluster not attributed by Proofpoint to a specific country, targeted a Vietnamese manufacturing organization using messages sent from a compromised Southeast Asian government email account. Successful BlueMoon exploitation initiated a DLL-sideloading infection chain that ultimately loaded a Rust executable into memory.
UNK_QuietRacket
A fourth cluster, suspected China-aligned UNK_QuietRacket, began using BlueMoon on September 3 against government, consulting, and financial organizations in Indonesia and Singapore. Its campaigns used conference-themed phishing lures and ultimately delivered a DLL-sideloading chain employing Google DNS-over-HTTPS and Cloudflare Workers for C2 activity.
Possible AI-Assisted Exploit Development
Proofpoint also identified development artifacts suggesting that BlueMoon may have been developed with AI assistance, although researchers emphasized that the evidence is not conclusive. Observed samples contained extensive diagnostic logging, verbose comments documenting previous failures and subsequent debugging iterations, and instructions requesting that exploit testers return complete logs. Researchers also identified a reference to a markdown handover document containing development history and rationale, an artifact Proofpoint noted is commonly used by AI agents to transfer context between sessions or models.
The exploit kit also exhibited operational security weaknesses atypical of historically high-value browser exploit chains. Its default post-exploitation behavior simply invokes curl to download and execute an attacker-provided payload, creating multiple high-signal opportunities for endpoint detection. Proofpoint assessed that the combination of rapid deployment, retained development artifacts, and comparatively weak operational security could indicate that speed was prioritized over stealth.
Analyst Commentary
BlueMoon demonstrates how quickly a high-value exploitation capability can move from development into operational use across otherwise distinct threat actor clusters. More importantly for defenders, the campaigns highlight the security implications of the open-source patch gap. Organizations may face active exploitation after security-relevant upstream code changes become publicly accessible but before a patched downstream product is broadly available.
The possible use of AI-assisted development could further compress this timeline. While Proofpoint’s findings do not establish that BlueMoon was created using AI, AI-enabled analysis and development tools could reduce the time and expertise required to examine security patches, reproduce vulnerabilities, troubleshoot exploit chains, and adapt working capabilities for operational deployment. Proofpoint assesses that BlueMoon itself is likely to proliferate further and that the broader model of rapidly exploiting open-source patch gaps is likely to recur.
This acceleration also complicates traditional malware detection. BlueMoon provided a common initial exploitation capability, but the actors using it deployed substantially different downstream payloads, ranging from a malicious browser extension and ShadowPad to Rust-based and custom malware. Defenders therefore cannot assume that identifying one payload or malware family will provide visibility across every campaign using the same exploitation framework.
PolySwarm helps organizations address this visibility gap by crowdsourcing malware detection across a diverse marketplace of commercial and specialized security engines. Rather than relying on the coverage of a single detection technology, security teams can use PolySwarm to evaluate suspicious artifacts against multiple independent detection approaches, compare verdicts, enrich threat investigations, and identify malicious files that may have limited coverage elsewhere.
IOCs
PolySwarm has multiple samples associated with this activity.
7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288
e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004
353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee
f3c64014221a58f3fde88e562662dbd5a1b3dd2b59c86e9e2bc5cb8f671664e7
87b6b24c06f99900a8aa579caedee1e402015884c925a98dcfb0fb38dfa2de22
ac6806c89e294f390838cb07c015dabec1c8ada06ce5161a0ad50b8a72828141
3594ad58fb6217fafe9839e53999a90608c2e9f335fa20aece3d53f8c0802726
3ec3151d8d1278ed966941ac89ea495ef6a80c70613dd9138cc85fc28c9df432
6e6378d8d404166da89d982e80bc52e19a3f677201258dec1775f100a027a92d
295fc584f75e94108c9be945977db33ed80421f5d374eab188587c911dffd915
bc7d24f5cf8937b334966201bdcce8ca9bab6ec5889d40a399d4094dcad73360
Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.
Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.