Insights, news, education and announcements from PolySwarm

BlueMoon Exploit Kit Rapidly Targets Key Verticals Across Multiple Espionage Campaigns

Written by The Hivemind | Sep 21, 2026, 5:13:44 PM

Verticals Targeted: Aerospace, Defense, Government, Financial, Manufacturing, Mining & Natural Resources, Nonprofit/NGO, Professional Services, Commodity Trading
Regions Targeted: US, Asia
Related Threat Actors: TA412 (Violet Typhoon), UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket
Related Families: BlueMoon, GemStone, ShadowPad

Executive Summary

Four espionage-focused threat actors were observed using BlueMoon, a newly tracked exploit kit chaining two Chromium V8 vulnerabilities with a Windows kernel privilege-escalation flaw. First observed in late August 2026, BlueMoon spread rapidly among mostly China-aligned clusters targeting organizations across the United States and Asia. Campaigns delivered payloads including GemStone and ShadowPad. Researchers also identified artifacts consistent with possible AI-assisted development, although evidence remains inconclusive. Proofpoint warns the kit may proliferate further as attackers increasingly exploit open-source patch gaps before downstream security updates reach users.

Key Takeaways

  • BlueMoon chains three vulnerabilities, CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, to achieve browser exploitation, sandbox escape, and privilege escalation on vulnerable Windows systems.
  • At least four espionage-focused threat actor clusters adopted BlueMoon within days, targeting US NGOs, mining, commodity trading, and aerospace organizations as well as government, financial, consulting, and manufacturing entities in Asia.
  • Post-exploitation payloads varied by operator, including TA412’s GemStone credential-theft and browser-surveillance extension, ShadowPad, a Rust-based loader chain, and unidentified custom malware.
  • BlueMoon highlights the risk posed by open-source patch gaps, where attackers may reverse engineer publicly available security fixes before patched downstream releases reach users. Development artifacts also suggest possible AI assistance, although Proofpoint found no conclusive evidence confirming AI involvement.

What is BlueMoon Exploit Kit?

Proofpoint researchers identified multiple espionage-motivated threat actors rapidly adopting BlueMoon beginning in late August 2026. The first observed user was China-aligned TA412, also known as APT31, JungleBamboo, Violet Typhoon, and TIDE CASTLE, on August 28. Within days, several additional espionage-focused clusters began deploying the same exploit kit, with most observed activity having a suspected China nexus. Proofpoint cautioned, however, that available evidence does not establish BlueMoon as exclusive to China-aligned operators.

BlueMoon combines three vulnerabilities to progress from browser exploitation to elevated execution on Windows. The chain begins with CVE-2026-85046, a type-confusion vulnerability in Chromium’s V8 JavaScript engine, followed by CVE-2026-87491, an out-of-bounds write vulnerability in V8 that BlueMoon uses for sandbox escape. The kit then uses CVE-2026-85880, a Windows kernel local privilege escalation vulnerability affecting older Windows builds, to elevate the compromised browser renderer process.

Both V8 vulnerabilities were “patch-gap” zero-days when Proofpoint observed exploitation. Although fixes were already publicly available in upstream Chromium source code, they had not yet reached stable Chrome and other Chromium-based browser releases. The fix for CVE-2026-85046, for example, was committed on August 7 but was not incorporated into the general stable Chromium build until September 3. This created a nearly four-week window in which the code change could potentially be analyzed and weaponized before most users received a patched browser.

Following successful browser exploitation, BlueMoon reflectively loads a DLL to fingerprint the Windows host and determine whether it is compatible with the LPE stage. After privilege escalation, a separate injector shellcode reaches the parent Chrome broker process and executes an operator-specified command. BlueMoon’s default configuration uses curl to retrieve an executable, save it to the Windows %TEMP% directory, and execute it.

Multiple Espionage Actors Rapidly Adopt BlueMoon

TA412

TA412 initially deployed BlueMoon against a small number of US NGOs, mining companies, and physical commodity trading organizations. Its spearphishing campaigns used several social-engineering themes, including messages impersonating university students seeking internships and outreach related to an upcoming academic conference. In some cases, the actor first established rapport with targeted individuals before sending a malicious link. Victims who followed the link reached actor-controlled infrastructure hosting BlueMoon. The page attempted browser exploitation while displaying a loading screen and subsequently redirected the victim to a legitimate website. Successful exploitation delivered a loader that installed a malicious Chromium extension tracked by Proofpoint as GemStone.

GemStone masquerades as an “AI-powered browsing companion by Google Gemini” but functions as a browser-surveillance and credential-theft backdoor. Its capabilities include collecting cookies, browser storage, session information, keystrokes, navigation data, and screenshots. Operators can remotely trigger additional collection, inject the malware’s keylogger into browser tabs, specify keywords to monitor, and execute arbitrary HTTP requests from the browser-extension context.

UNK_LateNight

Beginning September 2, China-aligned UNK_LateNight targeted US aerospace companies using business-to-business and request-for-quotation phishing lures associated with the US defense industrial base. Successful exploitation ultimately deployed the ShadowPad backdoor, which established persistence through a scheduled task and included capabilities for Firefox profile theft and network traffic collection.

UNK_DoubleCheck

Also on September 2, UNK_DoubleCheck, an espionage-motivated cluster not attributed by Proofpoint to a specific country, targeted a Vietnamese manufacturing organization using messages sent from a compromised Southeast Asian government email account. Successful BlueMoon exploitation initiated a DLL-sideloading infection chain that ultimately loaded a Rust executable into memory.

UNK_QuietRacket

A fourth cluster, suspected China-aligned UNK_QuietRacket, began using BlueMoon on September 3 against government, consulting, and financial organizations in Indonesia and Singapore. Its campaigns used conference-themed phishing lures and ultimately delivered a DLL-sideloading chain employing Google DNS-over-HTTPS and Cloudflare Workers for C2 activity.

Possible AI-Assisted Exploit Development

Proofpoint also identified development artifacts suggesting that BlueMoon may have been developed with AI assistance, although researchers emphasized that the evidence is not conclusive. Observed samples contained extensive diagnostic logging, verbose comments documenting previous failures and subsequent debugging iterations, and instructions requesting that exploit testers return complete logs. Researchers also identified a reference to a markdown handover document containing development history and rationale, an artifact Proofpoint noted is commonly used by AI agents to transfer context between sessions or models.

The exploit kit also exhibited operational security weaknesses atypical of historically high-value browser exploit chains. Its default post-exploitation behavior simply invokes curl to download and execute an attacker-provided payload, creating multiple high-signal opportunities for endpoint detection. Proofpoint assessed that the combination of rapid deployment, retained development artifacts, and comparatively weak operational security could indicate that speed was prioritized over stealth.

Analyst Commentary

BlueMoon demonstrates how quickly a high-value exploitation capability can move from development into operational use across otherwise distinct threat actor clusters. More importantly for defenders, the campaigns highlight the security implications of the open-source patch gap. Organizations may face active exploitation after security-relevant upstream code changes become publicly accessible but before a patched downstream product is broadly available.

The possible use of AI-assisted development could further compress this timeline. While Proofpoint’s findings do not establish that BlueMoon was created using AI, AI-enabled analysis and development tools could reduce the time and expertise required to examine security patches, reproduce vulnerabilities, troubleshoot exploit chains, and adapt working capabilities for operational deployment. Proofpoint assesses that BlueMoon itself is likely to proliferate further and that the broader model of rapidly exploiting open-source patch gaps is likely to recur.

This acceleration also complicates traditional malware detection. BlueMoon provided a common initial exploitation capability, but the actors using it deployed substantially different downstream payloads, ranging from a malicious browser extension and ShadowPad to Rust-based and custom malware. Defenders therefore cannot assume that identifying one payload or malware family will provide visibility across every campaign using the same exploitation framework.

PolySwarm helps organizations address this visibility gap by crowdsourcing malware detection across a diverse marketplace of commercial and specialized security engines. Rather than relying on the coverage of a single detection technology, security teams can use PolySwarm to evaluate suspicious artifacts against multiple independent detection approaches, compare verdicts, enrich threat investigations, and identify malicious files that may have limited coverage elsewhere.

IOCs

PolySwarm has multiple samples associated with this activity.

 

7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288

e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004

353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98ee

f3c64014221a58f3fde88e562662dbd5a1b3dd2b59c86e9e2bc5cb8f671664e7

87b6b24c06f99900a8aa579caedee1e402015884c925a98dcfb0fb38dfa2de22

ac6806c89e294f390838cb07c015dabec1c8ada06ce5161a0ad50b8a72828141

3594ad58fb6217fafe9839e53999a90608c2e9f335fa20aece3d53f8c0802726

3ec3151d8d1278ed966941ac89ea495ef6a80c70613dd9138cc85fc28c9df432

6e6378d8d404166da89d982e80bc52e19a3f677201258dec1775f100a027a92d

295fc584f75e94108c9be945977db33ed80421f5d374eab188587c911dffd915

bc7d24f5cf8937b334966201bdcce8ca9bab6ec5889d40a399d4094dcad73360

 

Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.

Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.