Find notable cyber news and cases, enriched with sources, timelines, and signals.

BlueMoon exploit kit deployment across espionage clusters

Malware Activity
First reported
Last updated
Happening score
H score 34
2 unique sources, 3 articles

Summary

Hide ▲

BlueMoon is a shared exploit kit used in espionage campaigns that chain Google Chrome and Microsoft Windows flaws into code execution, browser sandbox escape, and Windows local privilege escalation. Proofpoint said it observed the kit in use since August 28, 2026, and Volexity later tied related activity to UTA0560 and JungleBamboo / APT31. The reported chains use CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, with follow-on delivery that included loaders, DLL sideloading, and a Chrome extension or backdoor payload. The activity targeted NGOs and other organizations, and CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on September 4.

Related Happenings

Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign

Campaign
H score35 First: 01.09.2026 16:08 Last: 01.09.2026 16:08 Sources 1

About this happening: Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation i...

Malicious Chrome and Edge browser-extension campaign

Campaign
H score16 First: 30.08.2026 17:17 Last: 30.08.2026 17:17 Sources 1

About this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...

Superior malicious extension installation campaign

Campaign
H score17 First: 28.08.2026 18:27 Last: 28.08.2026 18:27 Sources 1

About this happening: The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...

Microsoft August 2026 Patch Tuesday security updates (3 zero-days)

Security Patch Release
H score39 First: 11.08.2026 21:08 Last: 11.08.2026 21:08 Sources 1

About this happening: Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...

Latest development: 12.08.2026 16:35

Lazarus group malware used a post-quantum key exchange to negotiate its command channel, then pulled down a Windows zero-day exploit in an Operation Dream Job campaign against defense and aerospace companies in Europe and India. The chain ran through MISTPEN, an in-memory downloader that fetched FudModule v3.1, a kernel rootkit that disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger, blinds 94 ETW providers, and tampers with Smart App Control; the same infrastructure also used RelayShell and impersonation sites for Enveil to distribute Troy.

XCSSET v40 macOS malware activity via compromised Xcode projects

Malware Activity
H score30 First: 04.08.2026 22:03 Last: 04.08.2026 22:03 Sources 1

About this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...

Timeline

  1. 09.09.2026 19:34 2 articles · 12d ago

    APT31 delivers BlueMoon through spear-phishing to U.S. targets

    Exploitation Observed

    APT31, also tracked as Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon, used spear-phishing lures starting on August 28, 2026 to target NGOs, mining companies, and physical commodity trading firms in the U.S. A malicious link served BlueMoon, which then loaded a browser add-on disguised as Google Gemini and established the GemStone browser-surveillance and credential-theft backdoor.

    Show sources
  2. 09.09.2026 19:34 1 articles · 12d ago

    BlueMoon reaches U.S. aerospace companies and a Vietnamese manufacturer

    Campaign Scope Update

    Beginning on September 2, 2026, UNK_LateNight used spear-phishing lures against multiple U.S. aerospace companies, while UNK_DoubleCheck targeted a Vietnamese manufacturing entity and sent victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon. The chain used BlueMoon to trigger DLL sideloading, drop a Rust binary, and fetch a second sideloading pair from a Cloudflare R2 Bucket.

    Show sources
  3. 09.09.2026 19:34 1 articles · 12d ago

    BlueMoon lands on government, consulting, and financial targets in Indonesia and Singapore

    Campaign Scope Update

    Beginning on September 3, 2026, UNK_QuietRacket used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore. The landing pages deployed BlueMoon, which downloaded and executed a DLL sideloading pair, used Cloudflare Workers domains to fetch a .NET assembly in memory, and created a scheduled task to preserve persistence.

    Show sources
  4. 09.09.2026 19:34 1 articles · 12d ago

    CISA adds CVE-2026-85046 to the Known Exploited Vulnerabilities catalog

    Legal Policy Action Update

    On 4 September, CISA added the Chrome flaw CVE-2026-85046 to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies until 18 September to patch. The deadline followed Google's fix and underscored that downstream Chromium-based browsers can remain exposed until updates fully propagate.

    Show sources
  5. 09.09.2026 19:34 3 articles · 12d ago

    Proofpoint publishes BlueMoon analysis

    Initial Disclosure

    Proofpoint published analysis of BlueMoon as a previously undocumented exploit kit that chained CVE-2026-85046 in Google Chrome with CVE-2026-85880 in Windows ALPC. The report said the campaigns began with phishing emails, used BlueMoon to trigger code execution and browser sandbox escape, and then leveraged a Windows local privilege escalation path, reflectively loaded DLLs, and a curl-based downloader to deliver follow-on payloads.

    Show sources