Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports.
The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it on August 28. Within days, several other Chinese threat actors started using it, but the activity might not be exclusive to China-aligned groups.
“It is currently unknown how multiple distinct threat actors obtained access to the exploit kit. Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors,” Proofpoint notes.
The BlueMoon exploit kit was adopted fast because it chains together three vulnerabilities that were unpatched when it first emerged: two zero-days in Chrome and one in Windows.
Tracked as CVE-2026-85046 and CVE-2026-87491, the Chrome flaws were patched as zero-days on September 3 and September 8, respectively. Both impact the V8 JavaScript and WebAssembly engine.
The Windows zero-day, tracked as CVE-2026-85880, was fixed on September 2026 Patch Tuesday. It is a privilege escalation in Windows Advanced Local Procedure Call (ALPC).
BlueMoon, Proofpoint says, exploits the V8 defects for sandbox escape, then fingerprints the host and executes the privilege escalation code. Next, a CreateProcess stub is injected into the parent Chrome broker process to download an executable via a curl command and execute it.
Proofpoint identified several packaging variations of BlueMoon, all using the same underlying exploit chain and identical orchestration and loading mechanisms.
Retrieved development artifacts suggest that the exploit kit’s creators might have used AI to build it, “though no single artifact conclusively confirms this,” Proofpoint says.
BlueMoon was initially used by Violet Typhoon in attacks targeting NGOs in the US, as well as mining entities and physical commodity trading firms.
Starting September 2, a second China-linked espionage group, tracked as UNK_LateNight, used it against multiple US aerospace companies, and a threat actor tracked as UNK_DoubleCheck targeted a manufacturing organization in Vietnam.
The next day, Chinese espionage group UNK_QuietRacket started using it in attacks against government, consulting, and financial entities in Indonesia and Singapore.
“BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development,” Proofpoint notes.
Related: North Korean Hackers Deploy New Linux Espionage Toolkit
Related: Modified ScreenConnect Clients Used in Worm-Like Campaign
Related: AI Speeds Up Malware Development, Not Its Success Rate: Analysis
Related: Rust Supply Chain Attack Linked to North Korean Hackers

