The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

BlueMoon Exploit Kit Rapidly Targets Key Verticals Across Multiple Espionage Campaigns

Sep 21, 2026, 1:13:44 PM / by The Hivemind posted in Threat Bulletin, BlueMoon exploit kit, BlueMoon exploit chain, Chrome zero-day exploit, BlueMoon cyberattack, Chromium zero-day

0 Comments

Verticals Targeted: Aerospace, Defense, Government, Financial, Manufacturing, Mining & Natural Resources, Nonprofit/NGO, Professional Services, Commodity Trading
Regions Targeted: US, Asia
Related Threat Actors: TA412 (Violet Typhoon), UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket
Related Families: BlueMoon, GemStone, ShadowPad

Executive Summary

Four espionage-focused threat actors were observed using BlueMoon, a newly tracked exploit kit chaining two Chromium V8 vulnerabilities with a Windows kernel privilege-escalation flaw. First observed in late August 2026, BlueMoon spread rapidly among mostly China-aligned clusters targeting organizations across the United States and Asia. Campaigns delivered payloads including GemStone and ShadowPad. Researchers also identified artifacts consistent with possible AI-assisted development, although evidence remains inconclusive. Proofpoint warns the kit may proliferate further as attackers increasingly exploit open-source patch gaps before downstream security updates reach users.

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts