Threat reportVulnerabilityTL-2026-3185
BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 and CVE-2026-87491 with Windows Kernel LPE CVE-2026-85880
BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 (TL-2026-3185), also tracked as BlueMoon, is a critical-severity software vulnerability, first published 2026-10-10. It is attributed to APT31 (China) with medium confidence, affects Google Chrome / Chromium-based browsers (V8) on Windows, references 3 CVEs (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880), maps to 17 MITRE ATT&CK techniques (T1027, T1036.005, T1053.005), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 4APT31
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-3185
- Threat ID
- TL-2026-3185
- Also known as
- BlueMoon, BlueMoon exploit kit, BlueMoon exploit chain
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- APT31, UNK_DoubleCheck, UNK_QuietRacket, UTA0560
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- nonprofit, mining, commodity trading, aerospace, defense, manufacturing, government administration, consulting, finance
- Target regions
- united states of america, vietnam, indonesia, singapore
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046
Malware and tooling: GemStone, ShadowPad, ShadowPad
How BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 works
BlueMoon is an exploit kit first observed in the wild on 2026-08-28 that chains a Chrome V8 type confusion (CVE-2026-85046), a V8 sandbox escape via WebAssembly metadata corruption (CVE-2026-87491) and a Windows ALPC/WNF kernel privilege escalation (CVE-2026-85880). Proofpoint reports TA412 (APT31) and three other espionage clusters, most with a suspected China nexus, adopted it within about 12 days via spearphishing links to deliver GemStone, ShadowPad, a Rust loader and .NET-staged malware.
BlueMoon is a browser-to-SYSTEM exploit kit reported by Proofpoint (published 2026-09-09) and independently observed by Volexity, and summarised by Picus Security on 2026-10-08. A victim is lured by a phishing email to an actor-controlled URL (or, in the UTA0560 case, a legitimate US university website with a reflective XSS flaw used to redirect to attacker servers). The kit filters out hosts that are not Chrome on Windows, then runs the exploit inside a Web Worker, retrying up to five times.
Exploit chain: (1) CVE-2026-85046 is a type confusion in the V8 TurboFan JIT compiler, abused through Array.fill() mutation and Float64Array corruption to obtain read/write primitives inside the V8 sandbox. (2) CVE-2026-87491 escapes the V8 sandbox by corrupting WebAssembly compiled-function metadata so execution is redirected into attacker shellcode. (3) A reflective DLL fingerprints the Windows host, then CVE-2026-85880, a heap-based buffer overflow in the Windows ALPC subsystem abused together with WNF to gain kernel read/write, elevates the renderer; Proofpoint lists targeted builds 17763, 19041-19045, 20348 and 22000 (Windows 10, 11, Server 2019/2022). An injector shellcode then injects into the Chrome broker/parent process, which by default runs a curl command that downloads and executes an operator-specified file (default %TEMP%\msgbox.exe). The process tree chrome.exe -> cmd.exe -> curl.exe -> msgbox.exe is a key hunting artifact, as is the sessionStorage key v8ctf_exp_attempt. The exploit page accepted 13 URL parameters for testing, breakpoints, telemetry and controlled rollouts, and Proofpoint saw debugging comments suggesting AI-assisted development and references to Google's v8CTF.
Both V8 flaws were patch-gap zero-days: the fix for CVE-2026-85046 was committed to public Chromium source on 2026-08-07 but only reached Chrome stable on 2026-09-03 (27-day gap, Chrome 152.0.7977.82/.83); CVE-2026-87491 was patched 2026-09-08; CVE-2026-85880 was fixed in the September 2026 Patch Tuesday cumulative update. CISA added all three to KEV with due dates of 2026-09-18, 2026-09-22 and 2026-09-23 respectively. The LPE DLL compilation timestamp suggests CVE-2026-85880 may have been exploited as early as 2025.
Payloads by cluster: TA412 (APT31 / JungleBamboo / Violet Typhoon) deployed the SUPERSTOMP loader (C:\Users\Public\stomp_ext) that installs the GemStone/LONGTALE Chrome extension masquerading as a Gemini AI companion, providing keylogging, cookie and localStorage theft, screenshots and arbitrary HTTP requests, with C2 on Cloudflare Workers; SUPERSTOMP strips new preference hashes and forges legacy HMACs to bypass Chrome's November 2025 and June 2026 hardening. UNK_LateNight targeted US aerospace/defense with procurement lures and ShadowPad via DLL sideloading (encrypted payload A08744D2.tmp, scheduled task EdgeCore_AutoUpdate). UNK_DoubleCheck targeted a Vietnamese manufacturer using a compromised Southeast Asian government email account and a fake vaccination appointment, delivering a Rust loader that fetches DLL sideloading pairs from Cloudflare R2. UNK_QuietRacket targeted Indonesian and Singapore government, consulting and financial entities with conference lures, using in-memory .NET assemblies with DNS-over-HTTPS C2. Volexity separately tracked UTA0560 (from 2026-09-01), which used the same chain against NGOs to deliver the in-memory JScript backdoor GRIMWEDGE via msiexec.exe, with byte-identical shellcode shared with the JungleBamboo activity.
Attribution is China-aligned for TA412/APT31 (named by Proofpoint) and suspected for the other clusters; DoubleCheck attribution is pending. No CVSS scores were published in the sources reviewed, and no public PoC was cited.
MITRE ATT&CK techniques used in TL-2026-3185
Stealth
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Persistence
T1053.005 Scheduled Task; T1176.001 Browser Extensions; T1546.015 Component Object Model Hijacking
Privilege Escalation
Collection
T1056.001 Keylogging; T1113 Screen Capture
Execution
T1059.003 Windows Command Shell; T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.001 Malicious Link
Command and Control
Credential Access
T1539 Steal Web Session Cookie
Initial Access
stealth
Resource Development
Affected products and versions in BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046
- Google — Chrome / Chromium-based browsers (V8) on Windows
Vulnerable versions: Chrome stable builds before 152.0.7977.82/.83 (CVE-2026-85046); Builds before the 2026-09-08 update (CVE-2026-87491)
Fixed in: 152.0.7977.82/.83 (2026-09-03); 2026-09-08 update - Microsoft — Windows 10, Windows 11, Windows Server 2019/2022 (ALPC)
Vulnerable versions: Builds 17763, 19041-19045, 20348, 22000 prior to the September 2026 cumulative update
Fixed in: September 2026 Patch Tuesday cumulative update
Remediation for BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046
Patches
- Chrome stable 152.0.7977.82/.83 (2026-09-03) for CVE-2026-85046
- Chrome update of 2026-09-08 for CVE-2026-87491
- Microsoft September 2026 Patch Tuesday cumulative update for CVE-2026-85880 (KB numbers not specified in sources)
Immediate actions
- Update Chrome and Chromium-based browsers to 152.0.7977.82/.83 or later and apply the 2026-09-08 V8 sandbox escape fix (CVE-2026-87491)
- Apply the September 2026 Windows cumulative update for CVE-2026-85880 on Windows 10, 11 and Server 2019/2022
- Hunt for chrome.exe spawning cmd.exe and curl.exe, msgbox.exe in %TEMP%, C:\Users\Public\stomp_ext, and the listed scheduled tasks, mutex and registry key
- Block and monitor listed domains, hostnames and the IP address; review workers.dev and R2 egress
Workarounds
- Restrict the browser to patched versions via enterprise policy until updates deploy
- Brief users on spearphishing lures: internships, procurement inquiries, conference invitations, donation and vaccination-appointment themes
Longer-term hardening
- Track the gap between upstream Chromium fixes and Chrome stable releases and apply compensating controls during it
- Deploy behavioral EDR for process injection into the Chrome broker and anomalous browser child processes
- Enforce browser extension allow-listing and audit Chrome Preferences for tampered extension entries
- Apply least-privilege browser sandboxing policy and network segmentation
CVEs associated with BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046
Timeline of BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046
- V8 vulnerability reported to the Chromium project (per Volexity/Security Affairs).
- Fix for CVE-2026-85046 committed to public Chromium source, opening a 27-day patch gap before the stable release.
- Proofpoint observes first in-the-wild BlueMoon use by TA412 (APT31 / JungleBamboo / Violet Typhoon), delivering the GemStone Chrome extension.
- Volexity observes UTA0560 spearphishing NGOs with the chain via a reflective-XSS university site, delivering the GRIMWEDGE JScript backdoor.
- UNK_LateNight (ShadowPad, US aerospace/defense) and UNK_DoubleCheck (Rust loader, Vietnamese manufacturer) begin using BlueMoon.
- Chrome 152.0.7977.82/.83 ships with the CVE-2026-85046 fix; UNK_QuietRacket begins targeting Indonesian and Singapore organizations.
- Google patches the V8 sandbox escape CVE-2026-87491; Microsoft fixes CVE-2026-85880 in the September 2026 Patch Tuesday update.
- Proofpoint publishes 'Once in a BlueMoon' and Volexity publishes its UTA0560 analysis; ET signatures 2071919-2071924 and 2071996-2072001 released.
- CISA KEV remediation deadline for CVE-2026-85046; CVE-2026-85880 follows on 2026-09-22 and CVE-2026-87491 on 2026-09-23.
- Picus Security publishes its analysis of BlueMoon's exploitation of CVE-2026-85046 and CVE-2026-87491.
Sources cited for BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046
- How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491
- Proofpoint: Once in a BlueMoon - Multiple state-aligned threat actors rapidly adopt novel exploit chain
- BleepingComputer: New BlueMoon kit exploited Windows and Chrome zero-day flaws
- The Hacker News: Four spy groups used same Chrome and Windows zero-days
- Security Affairs: One Exploit Chain, Two Espionage Campaigns (Volexity UTA0560 / JungleBamboo)
- CSA Research Note: BlueMoon - One Exploit Kit, Four Nation-States, One Week
- The Record: China hackers Chrome browser zero-day multiple groups
- Cyber Security News: BlueMoon exploit chain
Detection coverage for TL-2026-3185
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3185 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.