BlueMoon exploit kit deployment across espionage clusters
Malware Activity
Summary
Hide ▲
Show ▼
BlueMoon is a shared exploit kit used in espionage campaigns that chain Google Chrome and Microsoft Windows flaws into code execution, browser sandbox escape, and Windows local privilege escalation. Proofpoint said it observed the kit in use since August 28, 2026, and Volexity later tied related activity to UTA0560 and JungleBamboo / APT31. The reported chains use CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, with follow-on delivery that included loaders, DLL sideloading, and a Chrome extension or backdoor payload. The activity targeted NGOs and other organizations, and CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on September 4.
Related Happenings
Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign
Campaign
H score35
First: 01.09.2026 16:08
Last: 01.09.2026 16:08
Sources 1
About this happening:
Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation i...
Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign
CampaignAbout this happening: Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation i...
Malicious Chrome and Edge browser-extension campaign
Campaign
H score16
First: 30.08.2026 17:17
Last: 30.08.2026 17:17
Sources 1
About this happening:
A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Malicious Chrome and Edge browser-extension campaign
CampaignAbout this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Superior malicious extension installation campaign
Campaign
H score17
First: 28.08.2026 18:27
Last: 28.08.2026 18:27
Sources 1
About this happening:
The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
Superior malicious extension installation campaign
CampaignAbout this happening: The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
Microsoft August 2026 Patch Tuesday security updates (3 zero-days)
Security Patch Release
H score39
First: 11.08.2026 21:08
Last: 11.08.2026 21:08
Sources 1
About this happening:
Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...
Microsoft August 2026 Patch Tuesday security updates (3 zero-days)
Security Patch ReleaseAbout this happening: Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...
Latest development: 12.08.2026 16:35
Lazarus group malware used a post-quantum key exchange to negotiate its command channel, then pulled down a Windows zero-day exploit in an Operation Dream Job campaign against defense and aerospace companies in Europe and India. The chain ran through MISTPEN, an in-memory downloader that fetched FudModule v3.1, a kernel rootkit that disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger, blinds 94 ETW providers, and tampers with Smart App Control; the same infrastructure also used RelayShell and impersonation sites for Enveil to distribute Troy.
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware Activity
H score30
First: 04.08.2026 22:03
Last: 04.08.2026 22:03
Sources 1
About this happening:
XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware ActivityAbout this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
Timeline
-
09.09.2026 19:34 2 articles · 12d ago
APT31 delivers BlueMoon through spear-phishing to U.S. targets
Exploitation ObservedAPT31, also tracked as Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon, used spear-phishing lures starting on August 28, 2026 to target NGOs, mining companies, and physical commodity trading firms in the U.S. A malicious link served BlueMoon, which then loaded a browser add-on disguised as Google Gemini and established the GemStone browser-surveillance and credential-theft backdoor.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE — thehackernews.com — 15.09.2026 08:31
-
09.09.2026 19:34 1 articles · 12d ago
BlueMoon reaches U.S. aerospace companies and a Vietnamese manufacturer
Campaign Scope UpdateBeginning on September 2, 2026, UNK_LateNight used spear-phishing lures against multiple U.S. aerospace companies, while UNK_DoubleCheck targeted a Vietnamese manufacturing entity and sent victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon. The chain used BlueMoon to trigger DLL sideloading, drop a Rust binary, and fetch a second sideloading pair from a Cloudflare R2 Bucket.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
-
09.09.2026 19:34 1 articles · 12d ago
BlueMoon lands on government, consulting, and financial targets in Indonesia and Singapore
Campaign Scope UpdateBeginning on September 3, 2026, UNK_QuietRacket used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore. The landing pages deployed BlueMoon, which downloaded and executed a DLL sideloading pair, used Cloudflare Workers domains to fetch a .NET assembly in memory, and created a scheduled task to preserve persistence.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
-
09.09.2026 19:34 1 articles · 12d ago
CISA adds CVE-2026-85046 to the Known Exploited Vulnerabilities catalog
Legal Policy Action UpdateOn 4 September, CISA added the Chrome flaw CVE-2026-85046 to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies until 18 September to patch. The deadline followed Google's fix and underscored that downstream Chromium-based browsers can remain exposed until updates fully propagate.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
-
09.09.2026 19:34 3 articles · 12d ago
Proofpoint publishes BlueMoon analysis
Initial DisclosureProofpoint published analysis of BlueMoon as a previously undocumented exploit kit that chained CVE-2026-85046 in Google Chrome with CVE-2026-85880 in Windows ALPC. The report said the campaigns began with phishing emails, used BlueMoon to trigger code execution and browser sandbox escape, and then leveraged a Windows local privilege escalation path, reflectively loaded DLLs, and a curl-based downloader to deliver follow-on payloads.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
- New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws — www.bleepingcomputer.com — 10.09.2026 17:11