Today's AI/ML headlines are brought to you by ThreatPerspective

Digital Event Horizon

Exploit Kit BlueMoon: A Sudden and Widespread Attack on Chromium-Based Browsers and Windows


At least four hacking groups, including some with ties to the Chinese government, have been caught using the same exploit kit, BlueMoon, which targets critical vulnerabilities in Chromium-based browsers and Windows. The kit was deployed rapidly and widely shared, highlighting the ease of adoption and proliferation of this type of capability. The widespread use of BlueMoon has sparked concerns about the security of Chromium-based browsers and Windows users.

  • BlueMoon is a sophisticated exploit kit used by at least four hacking groups, some with ties to the Chinese government.
  • The kit targets critical vulnerabilities in Chromium-based browsers and older versions of Windows.
  • The BlueMoon exploit kit chains three vulnerabilities together, allowing attackers to install malware of their choice.
  • The kit's widespread use is attributed to a "patch gap" in the Chromium supply chain and AI-based vulnerability discovery.
  • The four groups targeted by the kit are TA412, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket.
  • The kit may continue to be used despite the availability of patches for the targeted vulnerabilities.



  • A recent discovery by security firm Proofpoint has shed light on a sophisticated exploit kit known as BlueMoon, which has been actively used by at least four hacking groups, some of which have ties to the Chinese government. The exploit kit, which targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows, has been deployed rapidly and widely shared across multiple threat actors within days, sparking concerns about the ease of adoption and proliferation of this type of capability.

    The BlueMoon exploit kit, named after the Blue Moon, a rare lunar event, is a nearly identical kit that chains three vulnerabilities together, allowing attackers to install malware of their choice. The vulnerabilities targeted by the kit are in the V8 JavaScript engine of Chromium-based browsers and older versions of Windows, including Windows 10 and Windows Server 2019. The vulnerabilities are tracked as CVE-2026-85046 and CVE-2026-85880, respectively.

    The widespread use of the BlueMoon exploit kit is attributed to a "patch gap" in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Additionally, the use of AI-based vulnerability discovery has likely contributed to the kit's rapid development and deployment. AI agents can often spot vulnerabilities faster than humans, enabling threat actors to move quickly before a window of opportunity closes.

    The four groups targeted by the BlueMoon exploit kit are TA412, a China-aligned state-sponsored threat actor; UNK_LateNight, a China-aligned espionage group; UNK_DoubleCheck, a threat actor that targeted a Vietnamese manufacturing entity; and UNK_QuietRacket, a threat actor that targeted Singapore and Indonesia. The groups and targets included a wide range of organizations and companies, including non-governmental organizations, mining companies, and physical commodity trading firms in the US.

    The BlueMoon exploit kit may continue to be used despite the availability of patches for the vulnerabilities it targets. Proofpoint warned that the kit's ease of adoption and proliferation could lead to its continued use by espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers.

    In conclusion, the BlueMoon exploit kit represents a significant threat to the security of Chromium-based browsers and Windows users. The widespread use of this kit highlights the need for timely and effective patching of vulnerabilities, as well as the importance of addressing the "patch gap" in the Chromium supply chain. As the use of AI-based vulnerability discovery continues to grow, it is essential to stay vigilant and adapt to the rapidly evolving threat landscape.



    Related Information:
  • https://www.digitaleventhorizon.com/articles/Exploit-Kit-BlueMoon-A-Sudden-and-Widespread-Attack-on-Chromium-Based-Browsers-and-Windows-deh.shtml

  • https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85046

  • https://www.cvedetails.com/cve/CVE-2026-85046/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85880

  • https://www.cvedetails.com/cve/CVE-2026-85880/


  • Published: Thu Sep 10 08:38:42 2026 by llama3.2 3B Q4_K_M











    © Digital Event Horizon . All rights reserved.

    Privacy | Terms of Use | Contact Us