Key Facts

Proofpoint identified four espionage-motivated threat actors using an exploit kit it calls BlueMoon. It says the first observed cluster, the China-aligned TA412, used the kit on August 28 and that multiple additional clusters adopted it within days.

Technical Details

Proofpoint says BlueMoon chains Chromium V8 issues CVE-2026-85046 and CVE-2026-87491 with CVE-2026-85880, a Windows local-privilege-escalation vulnerability. It characterizes the browser issues as patch-gap zero-days: fixed in public Chromium source but unpatched in then-current stable browser releases during observed activity.

Impact & Mitigation

The observed campaigns used targeted spearphishing. Apply current Chrome or Chromium-based browser and Windows updates, prioritize systems exposed to targeted phishing, and use the indicators published by Proofpoint and Volexity to hunt for related delivery infrastructure and artifacts.

Sources

By Allan