At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organisations' networks in the US and Southeast Asia.
Proofpoint's threat hunters spotted the kit, which they named BlueMoon, and said its first observed use started on August 28. This is when a Beijing-backed crew tracked as TA412, also known as Violet Typhoon and APT31, used BlueMoon to repeatedly target non-governmental organisations, mining companies, and physical commodity trading firms in the US.
Just days later, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus, according to Proofpoint researchers. Mark Kelly, a threat researcher at Proofpoint, said the researchers don't know exactly who was targeted, nor how, and so far the damage appears limited.
The kit chains together three vulnerabilities: a V8 type confusion flaw (CVE-2026-85046) affecting all Chromium-based browsers, a Chrome V8 sandbox escape, and a privilege escalation vulnerability in Windows Advanced Local Procedure Call (CVE-2026-85880). Google patched the first bug in Chrome on September 3, and Microsoft patched the Windows flaw on Tuesday.
Proofpoint researchers noted that both V8 vulnerabilities are what's called "patch-gap" zero-days at the time of the observed activity, meaning they were known and fixed in upstream Chromium source code but remained unpatched in the latest stable releases for weeks. "It is likely that the exploit kit developer used these publicly available Chromium patches to weaponize the browser exploit chain," the researchers noted.
Attacks start with a phishing email that tricks victims into clicking an actor-controlled URL, triggering the browser bugs and then the Windows bug to download payloads including browser-surveillance malware and credential-stealing backdoors. In one campaign, the chain installed a malicious browser extension disguised as Google Gemini, tracked as GemStone, which allowed the spies to steal cookies, take screenshots, and inject a keylogger.