Threat reportVulnerabilityTL-2026-3185

BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 and CVE-2026-87491 with Windows Kernel LPE CVE-2026-85880

criticalACTIVE

BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 (TL-2026-3185), also tracked as BlueMoon, is a critical-severity software vulnerability, first published 2026-10-10. It is attributed to APT31 (China) with medium confidence, affects Google Chrome / Chromium-based browsers (V8) on Windows, references 3 CVEs (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880), maps to 17 MITRE ATT&CK techniques (T1027, T1036.005, T1053.005), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
3Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
4APT31
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-3185

Threat ID
TL-2026-3185
Also known as
BlueMoon, BlueMoon exploit kit, BlueMoon exploit chain
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
APT31, UNK_DoubleCheck, UNK_QuietRacket, UTA0560
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
nonprofit, mining, commodity trading, aerospace, defense, manufacturing, government administration, consulting, finance
Target regions
united states of america, vietnam, indonesia, singapore
Detection rules
9
Indicators of compromise
25

Malware and tooling in BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046

Malware and tooling: GemStone, ShadowPad, ShadowPad

How BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 works

BlueMoon is an exploit kit first observed in the wild on 2026-08-28 that chains a Chrome V8 type confusion (CVE-2026-85046), a V8 sandbox escape via WebAssembly metadata corruption (CVE-2026-87491) and a Windows ALPC/WNF kernel privilege escalation (CVE-2026-85880). Proofpoint reports TA412 (APT31) and three other espionage clusters, most with a suspected China nexus, adopted it within about 12 days via spearphishing links to deliver GemStone, ShadowPad, a Rust loader and .NET-staged malware.

BlueMoon is a browser-to-SYSTEM exploit kit reported by Proofpoint (published 2026-09-09) and independently observed by Volexity, and summarised by Picus Security on 2026-10-08. A victim is lured by a phishing email to an actor-controlled URL (or, in the UTA0560 case, a legitimate US university website with a reflective XSS flaw used to redirect to attacker servers). The kit filters out hosts that are not Chrome on Windows, then runs the exploit inside a Web Worker, retrying up to five times.

Exploit chain: (1) CVE-2026-85046 is a type confusion in the V8 TurboFan JIT compiler, abused through Array.fill() mutation and Float64Array corruption to obtain read/write primitives inside the V8 sandbox. (2) CVE-2026-87491 escapes the V8 sandbox by corrupting WebAssembly compiled-function metadata so execution is redirected into attacker shellcode. (3) A reflective DLL fingerprints the Windows host, then CVE-2026-85880, a heap-based buffer overflow in the Windows ALPC subsystem abused together with WNF to gain kernel read/write, elevates the renderer; Proofpoint lists targeted builds 17763, 19041-19045, 20348 and 22000 (Windows 10, 11, Server 2019/2022). An injector shellcode then injects into the Chrome broker/parent process, which by default runs a curl command that downloads and executes an operator-specified file (default %TEMP%\msgbox.exe). The process tree chrome.exe -> cmd.exe -> curl.exe -> msgbox.exe is a key hunting artifact, as is the sessionStorage key v8ctf_exp_attempt. The exploit page accepted 13 URL parameters for testing, breakpoints, telemetry and controlled rollouts, and Proofpoint saw debugging comments suggesting AI-assisted development and references to Google's v8CTF.

Both V8 flaws were patch-gap zero-days: the fix for CVE-2026-85046 was committed to public Chromium source on 2026-08-07 but only reached Chrome stable on 2026-09-03 (27-day gap, Chrome 152.0.7977.82/.83); CVE-2026-87491 was patched 2026-09-08; CVE-2026-85880 was fixed in the September 2026 Patch Tuesday cumulative update. CISA added all three to KEV with due dates of 2026-09-18, 2026-09-22 and 2026-09-23 respectively. The LPE DLL compilation timestamp suggests CVE-2026-85880 may have been exploited as early as 2025.

Payloads by cluster: TA412 (APT31 / JungleBamboo / Violet Typhoon) deployed the SUPERSTOMP loader (C:\Users\Public\stomp_ext) that installs the GemStone/LONGTALE Chrome extension masquerading as a Gemini AI companion, providing keylogging, cookie and localStorage theft, screenshots and arbitrary HTTP requests, with C2 on Cloudflare Workers; SUPERSTOMP strips new preference hashes and forges legacy HMACs to bypass Chrome's November 2025 and June 2026 hardening. UNK_LateNight targeted US aerospace/defense with procurement lures and ShadowPad via DLL sideloading (encrypted payload A08744D2.tmp, scheduled task EdgeCore_AutoUpdate). UNK_DoubleCheck targeted a Vietnamese manufacturer using a compromised Southeast Asian government email account and a fake vaccination appointment, delivering a Rust loader that fetches DLL sideloading pairs from Cloudflare R2. UNK_QuietRacket targeted Indonesian and Singapore government, consulting and financial entities with conference lures, using in-memory .NET assemblies with DNS-over-HTTPS C2. Volexity separately tracked UTA0560 (from 2026-09-01), which used the same chain against NGOs to deliver the in-memory JScript backdoor GRIMWEDGE via msiexec.exe, with byte-identical shellcode shared with the JungleBamboo activity.

Attribution is China-aligned for TA412/APT31 (named by Proofpoint) and suspected for the other clusters; DoubleCheck attribution is pending. No CVSS scores were published in the sources reviewed, and no public PoC was cited.

MITRE ATT&CK techniques used in TL-2026-3185

Stealth

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Persistence

T1053.005 Scheduled Task; T1176.001 Browser Extensions; T1546.015 Component Object Model Hijacking

Privilege Escalation

T1055 Process Injection

Collection

T1056.001 Keylogging; T1113 Screen Capture

Execution

T1059.003 Windows Command Shell; T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.001 Malicious Link

Command and Control

T1071.001 Web Protocols

Credential Access

T1539 Steal Web Session Cookie

Initial Access

T1566.002 Spearphishing Link

stealth

T1574.001 DLL

Resource Development

T1583.001 Domains

Affected products and versions in BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046

  • Google — Chrome / Chromium-based browsers (V8) on Windows
    Vulnerable versions: Chrome stable builds before 152.0.7977.82/.83 (CVE-2026-85046); Builds before the 2026-09-08 update (CVE-2026-87491)
    Fixed in: 152.0.7977.82/.83 (2026-09-03); 2026-09-08 update
  • Microsoft — Windows 10, Windows 11, Windows Server 2019/2022 (ALPC)
    Vulnerable versions: Builds 17763, 19041-19045, 20348, 22000 prior to the September 2026 cumulative update
    Fixed in: September 2026 Patch Tuesday cumulative update

Remediation for BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046

Patches

  • Chrome stable 152.0.7977.82/.83 (2026-09-03) for CVE-2026-85046
  • Chrome update of 2026-09-08 for CVE-2026-87491
  • Microsoft September 2026 Patch Tuesday cumulative update for CVE-2026-85880 (KB numbers not specified in sources)

Immediate actions

  • Update Chrome and Chromium-based browsers to 152.0.7977.82/.83 or later and apply the 2026-09-08 V8 sandbox escape fix (CVE-2026-87491)
  • Apply the September 2026 Windows cumulative update for CVE-2026-85880 on Windows 10, 11 and Server 2019/2022
  • Hunt for chrome.exe spawning cmd.exe and curl.exe, msgbox.exe in %TEMP%, C:\Users\Public\stomp_ext, and the listed scheduled tasks, mutex and registry key
  • Block and monitor listed domains, hostnames and the IP address; review workers.dev and R2 egress

Workarounds

  • Restrict the browser to patched versions via enterprise policy until updates deploy
  • Brief users on spearphishing lures: internships, procurement inquiries, conference invitations, donation and vaccination-appointment themes

Longer-term hardening

  • Track the gap between upstream Chromium fixes and Chrome stable releases and apply compensating controls during it
  • Deploy behavioral EDR for process injection into the Chrome broker and anomalous browser child processes
  • Enforce browser extension allow-listing and audit Chrome Preferences for tampered extension entries
  • Apply least-privilege browser sandboxing policy and network segmentation

CVEs associated with BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046

CVE-2026-85046, CVE-2026-87491, CVE-2026-85880

Timeline of BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046

  • V8 vulnerability reported to the Chromium project (per Volexity/Security Affairs).
  • Fix for CVE-2026-85046 committed to public Chromium source, opening a 27-day patch gap before the stable release.
  • Proofpoint observes first in-the-wild BlueMoon use by TA412 (APT31 / JungleBamboo / Violet Typhoon), delivering the GemStone Chrome extension.
  • Volexity observes UTA0560 spearphishing NGOs with the chain via a reflective-XSS university site, delivering the GRIMWEDGE JScript backdoor.
  • UNK_LateNight (ShadowPad, US aerospace/defense) and UNK_DoubleCheck (Rust loader, Vietnamese manufacturer) begin using BlueMoon.
  • Chrome 152.0.7977.82/.83 ships with the CVE-2026-85046 fix; UNK_QuietRacket begins targeting Indonesian and Singapore organizations.
  • Google patches the V8 sandbox escape CVE-2026-87491; Microsoft fixes CVE-2026-85880 in the September 2026 Patch Tuesday update.
  • Proofpoint publishes 'Once in a BlueMoon' and Volexity publishes its UTA0560 analysis; ET signatures 2071919-2071924 and 2071996-2072001 released.
  • CISA KEV remediation deadline for CVE-2026-85046; CVE-2026-85880 follows on 2026-09-22 and CVE-2026-87491 on 2026-09-23.
  • Picus Security publishes its analysis of BlueMoon's exploitation of CVE-2026-85046 and CVE-2026-87491.

Sources cited for BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046

Detection coverage for TL-2026-3185

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3185 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats