Key Facts
Proofpoint identified four espionage-motivated threat actors using an exploit kit it calls BlueMoon. It says the first observed cluster, the China-aligned TA412, used the kit on August 28 and that multiple additional clusters adopted it within days.
Technical Details
Proofpoint says BlueMoon chains Chromium V8 issues CVE-2026-85046 and CVE-2026-87491 with CVE-2026-85880, a Windows local-privilege-escalation vulnerability. It characterizes the browser issues as patch-gap zero-days: fixed in public Chromium source but unpatched in then-current stable browser releases during observed activity.
Impact & Mitigation
The observed campaigns used targeted spearphishing. Apply current Chrome or Chromium-based browser and Windows updates, prioritize systems exposed to targeted phishing, and use the indicators published by Proofpoint and Volexity to hunt for related delivery infrastructure and artifacts.
