BlueMoon exploit kit chains Chrome and Windows zero-days
BlueMoon chains two Chrome V8 zero-days with a Windows ALPC privilege escalation and has been rapidly adopted by multiple espionage groups, Proofpoint reports.
Proofpoint reports that the BlueMoon exploit kit links two Chrome V8 zero-days (CVE-2026-85046 and CVE-2026-87491) with a Windows ALPC privilege-escalation zero-day (CVE-2026-85880). The kit was observed in use by multiple espionage-aligned groups starting in late August.
BlueMoon exploits the V8 defects to escape Chrome’s sandbox, fingerprints the host, then runs the ALPC privilege-escalation code to obtain higher system privileges. After escalation, the kit injects a CreateProcess stub into the parent Chrome broker process to download and execute an executable via a curl command. Researchers identified several packaging variations that share the same exploit chain and loading mechanisms.
The first recorded use was traced to the China-linked APT Violet Typhoon on August 28, targeting U.S.-based non-governmental organizations, mining firms and physical commodity trading companies. Within days other operators began using the same kit. Starting September 2, an actor tracked as UNK_LateNight targeted multiple U.S. aerospace companies; UNK_DoubleCheck targeted a manufacturing firm in Vietnam; and on September 3 UNK_QuietRacket used the exploit against government, consulting and financial entities in Indonesia and Singapore.
The two Chrome flaws were patched as zero-days on September 3 and September 8, respectively. The Windows ALPC vulnerability was fixed on the September 2026 Patch Tuesday. Because the fixes were released on different dates, there was a period when the vulnerabilities could be chained to move from a browser escape to elevated code execution.
Analysis recovered development artifacts that suggest the kit’s creators may have used artificial intelligence tools during build and testing, though no single artifact conclusively proves AI involvement. Researchers also noted that it remains unclear how multiple distinct actors obtained access to the exploit kit.
On the kit’s spread, Proofpoint warned: “Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors.”







