The BlueMoon exploit chain: how three zero-days fit together
Proofpoint researchers identified an exploit chain they call BlueMoon that links three zero-day vulnerabilities to give attackers full access to targeted machines. The chain targets Chrome and other Chromium-based browsers and Microsoft Windows: two remote-code execution defects in the browser JavaScript engine — CVE-2026-85046 and CVE-2026-87491 — and a Windows privilege-escalation zero-day, CVE-2026-85880, in the Advanced Local Procedure Call (ALPC) interface. According to Proofpoint, the chain allows attackers to run code in the browser’s sandbox, escape the sandbox and gain system privileges to reach a targeted device.
APT31 (TA412) led the first wave; at least three other groups followed
Proofpoint says the China-aligned espionage group it tracks as TA412 — also known as Violet Typhoon and APT31 — exploited the BlueMoon chain first on Aug. 28. APT31 used phishing emails to deliver the loader to non-governmental organizations, mining companies and commodity trading firms in the United States. At least three additional espionage-motivated groups then adopted the same vulnerabilities in subsequent waves of attacks days later, with activity peaking Sept. 2–3 and continuing intermittently through at least Sept. 8.
Researchers named the follow-on actors and their observed targets: UNK_LateNight targeted multiple U.S. aerospace companies on Sept. 2; UNK_DoubleCheck was observed the same day targeting Vietnamese manufacturing organizations using emails sent from a compromised Southeast Asian government account; and UNK_QuietRacket targeted government, consulting and financial organizations in Indonesia and Singapore on Sept. 3. Proofpoint attributes most of the observed attacks to Chinese espionage groups and notes APT31 has a history of committing espionage on behalf of China’s Ministry of State Security, including seven Chinese nationals indicted by the Justice Department in 2024.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTechnical details: public patches lagged source fixes and the exploit developer acted fast
Proofpoint’s account emphasizes a narrow window during which attackers could weaponize fixes visible in Chromium source code but not yet present in the latest publicly distributed browsers. Kelly explained that while the V8 (JavaScript engine) vulnerabilities were known and fixed in Chromium source code, they were “not yet patched in the latest publicly available browsers at the time of the activity, meaning they effectively functioned as zero-days in those products.”
Proofpoint further states the exploit kit developer likely reverse engineered the Chromium patches to create a usable browser exploit during that gap. Microsoft’s privilege-escalation issue, CVE-2026-85880, was disclosed by Microsoft “Tuesday” in the Windows ALPC component, and the three vulnerabilities together enabled the end-to-end BlueMoon chain.
Delivery methods and operational tempo
Observed intrusions used phishing lures and rapid infrastructure staging. In the initial APT31 activity, phishing links installed a malicious browser extension disguised as Google Gemini; that extension permitted attackers to surveil browser activity, steal credentials and execute commands. Proofpoint noted that in all observed cases, the infrastructure used for exploit delivery was created on the same day as — or in the days immediately preceding — the associated campaigns, suggesting rushed development and a narrow targeting window.
What this means for U.S. aerospace companies, Vietnamese manufacturers, and governments and firms in Indonesia and Singapore
- U.S. aerospace companies: several were targeted by UNK_LateNight on Sept. 2. They will need to verify whether any of their systems were reached via browser exploits or subsequent privilege escalation, and to check whether any attackers used stolen credentials or persistent browser extensions.
- Vietnamese manufacturing organizations: Proofpoint observed UNK_DoubleCheck targeting these firms using emails from a compromised Southeast Asian government account, increasing the chance that trusted-sender heuristics were abused; victims should audit inbound email sources and any extensions installed after Sept. 1.
- Governments, consulting and financial firms in Indonesia and Singapore: UNK_QuietRacket’s Sept. 3 activity placed these sectors on notice that browser-based zero-days plus a Windows escalation exploit were being used for espionage across the region.
Proofpoint has directly observed fewer than 20 organizations targeted globally so far, but Kelly warned the true number is likely much higher. Given the exploit kit’s relative ease of adoption and the fact that two V8 fixes were visible in Chromium source prior to browser patches, Proofpoint expects the BlueMoon kit to proliferate across both espionage-motivated and financially motivated threat actors as patched browser versions are fully rolled out.
The immediate lesson from these events is the speed with which actors can turn source-code fixes into weaponized exploits when public builds lag. The story ends on two linked practical questions left open by the observed activity: how quickly will patched Chromium-based browsers reach all users, and how rapidly will defenders find and remove browser extensions or credentials obtained during the narrow window before patches were applied?




