# BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 and CVE-2026-87491 with Windows Kernel LPE CVE-2026-85880

> BlueMoon is an exploit kit first observed in the wild on 2026-08-28 that chains a Chrome V8 type confusion (CVE-2026-85046), a V8 sandbox escape via WebAssembly metadata corruption (CVE-2026-87491) and a Windows ALPC/WNF kernel privilege escalation (CVE-2026-85880). Proofpoint reports TA412 (APT31) and three other espionage clusters, most with a suspected China nexus, adopted it within about 12 days via spearphishing links to deliver GemStone, ShadowPad, a Rust loader and .NET-staged malware.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3185
- **ID:** TL-2026-3185
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** APT31 (China)
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-85046, CVE-2026-87491, CVE-2026-85880

## Description

BlueMoon is a browser-to-SYSTEM exploit kit reported by Proofpoint (published 2026-09-09) and independently observed by Volexity, and summarised by Picus Security on 2026-10-08. A victim is lured by a phishing email to an actor-controlled URL (or, in the UTA0560 case, a legitimate US university website with a reflective XSS flaw used to redirect to attacker servers). The kit filters out hosts that are not Chrome on Windows, then runs the exploit inside a Web Worker, retrying up to five times.

Exploit chain: (1) CVE-2026-85046 is a type confusion in the V8 TurboFan JIT compiler, abused through Array.fill() mutation and Float64Array corruption to obtain read/write primitives inside the V8 sandbox. (2) CVE-2026-87491 escapes the V8 sandbox by corrupting WebAssembly compiled-function metadata so execution is redirected into attacker shellcode. (3) A reflective DLL fingerprints the Windows host, then CVE-2026-85880, a heap-based buffer overflow in the Windows ALPC subsystem abused together with WNF to gain kernel read/write, elevates the renderer; Proofpoint lists targeted builds 17763, 19041-19045, 20348 and 22000 (Windows 10, 11, Server 2019/2022). An injector shellcode then injects into the Chrome broker/parent process, which by default runs a curl command that downloads and executes an operator-specified file (default %TEMP%\msgbox.exe). The process tree chrome.exe -> cmd.exe -> curl.exe -> msgbox.exe is a key hunting artifact, as is the sessionStorage key v8ctf_exp_attempt. The exploit page accepted 13 URL parameters for testing, breakpoints, telemetry and controlled rollouts, and Proofpoint saw debugging comments suggesting AI-assisted development and references to Google's v8CTF.

Both V8 flaws were patch-gap zero-days: the fix for CVE-2026-85046 was committed to public Chromium source on 2026-08-07 but only reached Chrome stable on 2026-09-03 (27-day gap, Chrome 152.0.7977.82/.83); CVE-2026-87491 was patched 2026-09-08; CVE-2026-85880 was fixed in the September 2026 Patch Tuesday cumulative update. CISA added all three to KEV with due dates of 2026-09-18, 2026-09-22 and 2026-09-23 respectively. The LPE DLL compilation timestamp suggests CVE-2026-85880 may have been exploited as early as 2025.

Payloads by cluster: TA412 (APT31 / JungleBamboo / Violet Typhoon) deployed the SUPERSTOMP loader (C:\Users\Public\stomp_ext) that installs the GemStone/LONGTALE Chrome extension masquerading as a Gemini AI companion, providing keylogging, cookie and localStorage theft, screenshots and arbitrary HTTP requests, with C2 on Cloudflare Workers; SUPERSTOMP strips new preference hashes and forges legacy HMACs to bypass Chrome's November 2025 and June 2026 hardening. UNK_LateNight targeted US aerospace/defense with procurement lures and ShadowPad via DLL sideloading (encrypted payload A08744D2.tmp, scheduled task EdgeCore_AutoUpdate). UNK_DoubleCheck targeted a Vietnamese manufacturer using a compromised Southeast Asian government email account and a fake vaccination appointment, delivering a Rust loader that fetches DLL sideloading pairs from Cloudflare R2. UNK_QuietRacket targeted Indonesian and Singapore government, consulting and financial entities with conference lures, using in-memory .NET assemblies with DNS-over-HTTPS C2. Volexity separately tracked UTA0560 (from 2026-09-01), which used the same chain against NGOs to deliver the in-memory JScript backdoor GRIMWEDGE via msiexec.exe, with byte-identical shellcode shared with the JungleBamboo activity.

Attribution is China-aligned for TA412/APT31 (named by Proofpoint) and suspected for the other clusters; DoubleCheck attribution is pending. No CVSS scores were published in the sources reviewed, and no public PoC was cited.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1059.007 JavaScript
- T1059.003 Windows Command Shell
- T1055 Process Injection
- T1053.005 Scheduled Task
- T1176.001 Browser Extensions
- T1574.001 DLL
- T1546.015 Component Object Model Hijacking
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1539 Steal Web Session Cookie
- T1056.001 Keylogging
- T1113 Screen Capture
- T1071.001 Web Protocols
- T1583.001 Domains

## Sources

- [How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491](https://www.picussecurity.com/resource/blog/how-bluemoon-exploits-chrome-cve-2026-85046-and-cve-2026-87491)
- [Proofpoint: Once in a BlueMoon - Multiple state-aligned threat actors rapidly adopt novel exploit chain](https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit)
- [BleepingComputer: New BlueMoon kit exploited Windows and Chrome zero-day flaws](https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/)
- [The Hacker News: Four spy groups used same Chrome and Windows zero-days](https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html)
- [Security Affairs: One Exploit Chain, Two Espionage Campaigns (Volexity UTA0560 / JungleBamboo)](https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html)
- [CSA Research Note: BlueMoon - One Exploit Kit, Four Nation-States, One Week](https://labs.cloudsecurityalliance.org/research/csa-research-note-bluemoon-exploit-kit-multi-actor-20260913/)
- [The Record: China hackers Chrome browser zero-day multiple groups](https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups)
- [Cyber Security News: BlueMoon exploit chain](https://cybersecuritynews.com/bluemoon-exploit-chain/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3185
