Four groups caught using the same Chrome and Windows exploit kit

Proofpoint’s latest briefing shines a harsh light on a new exploit kit—dubbed “BlueMoon”—that is rapidly reshaping the threat landscape. What BlueMoon Is and How It Works BlueMoon is not a single exploit but a chain that links three separate flaws.

Sep 10, 2026 - 19:03
0 3
Four groups caught using the same Chrome and Windows exploit kit

Proofpoint’s latest briefing shines a harsh light on a new exploit kit—dubbed “BlueMoon”—that is rapidly reshaping the threat landscape. The kit stitches together three fresh vulnerabilities, two in Chromium’s V8 JavaScript engine and one in the Windows kernel, allowing attackers to drop any malware they choose. Within days, at least four distinct hacking groups, some with alleged ties to the Chinese government, have weaponized the same kit, exposing a troubling “patch‑gap” window that cyber‑defenders have struggled to close.

What BlueMoon Is and How It Works

BlueMoon is not a single exploit but a chain that links three separate flaws. Two of those flaws sit in V8, the open‑source JavaScript engine that powers Chrome, Edge and other Chromium‑based browsers. One is a type‑confusion bug (tracked as CVE‑2026‑85046) and the other a sandbox‑escape, both of which let malicious code run in the browser’s process. The third flaw is a local privilege‑escalation bug in the Windows kernel (CVE‑2026‑85880) that affects Windows 10 (Oct. 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11.

When a victim visits a compromised site, the V8 bugs let the attacker execute code in the browser. That code then leverages the Windows kernel bug to elevate its privileges to system level, opening the door for any payload—ransomware, espionage tools, or data‑stealers—to be installed. Proofpoint notes that all three vulnerabilities were patched within the past 24 hours, yet the kit’s rapid deployment means many systems remain exposed while patches roll out.

The “Patch Gap” Exploited

Proofpoint’s analysts point to a “patch‑gap” in the Chromium supply chain as a key enabler. Once Google releases a patch in the upstream Chromium source, downstream browsers like Chrome and Edge must incorporate it into their next stable release. That lag creates a window where the vulnerability is publicly known but still unpatched in users’ browsers. BlueMoon’s developers appear to have mined that window, reverse‑engineering the public patches to weaponize the zero‑day V8 bugs before downstream browsers could ship the fix.

This supply‑chain lag is not new, but the speed with which BlueMoon was assembled—within days of the patches becoming public—suggests a new level of efficiency, likely driven by AI‑assisted vulnerability discovery. Proofpoint warns that AI tools can spot and exploit flaws faster than human researchers, compressing the window even further and lowering the barrier to entry for threat actors.

Who Is Using BlueMoon?

Proofpoint identified four groups that have deployed the kit. The first, known as TA412, launched an attack on August 28. The other three groups began operations earlier in September. While the briefing does not name the other actors, it notes that at least some have ties to the Chinese government, hinting at state‑backed espionage motives alongside typical financially driven cybercrime.

The attacks have been anything but stealthy. Unlike many campaigns that limit exploit use to extend longevity, BlueMoon’s operators have been noisy, likely because the kit’s high detection signals are offset by the immediate payoff of exploiting a fresh patch gap. Proofpoint cautions that the kit’s ease of adoption means it could quickly spread to additional espionage‑motivated and financially motivated actors as patched browsers become the norm.

Impact on Targets

The four groups cast a wide net, hitting a diverse set of organizations and companies. While the source material does not enumerate specific victims, the breadth of the target list underscores the kit’s versatility. By chaining browser and OS exploits, attackers can breach both web‑facing and internal systems, making BlueMoon a potent tool for stealing intellectual property, installing ransomware, or establishing long‑term footholds.

Because the Windows kernel bug affects multiple versions of Windows 10, Windows Server and the early Windows 11 release, any enterprise still running legacy systems is at risk. The fact that the exploit chain can deliver “malware of their choice” means the ultimate impact varies widely—from data exfiltration to disruptive attacks that cripple operations.

Why AI Matters in the Threat Landscape

Proofpoint highlights AI as a likely catalyst behind BlueMoon’s rapid development. By automating the search for code patterns that could be vulnerable, AI can flag potential exploits faster than manual analysis. In the case of Chromium’s open‑source V8 engine, publicly available patches provide a rich dataset for AI models to learn from, enabling them to reverse‑engineer exploit code in a matter of days.

This shift has broader implications. If AI lowers the cost and skill barrier for creating sophisticated exploit chains, we may see a surge in similar kits targeting other open‑source projects. The open nature of codebases like Chromium, while essential for innovation, also furnishes threat actors with the raw material they need to craft attacks at unprecedented speed.

Defensive Recommendations

Organizations must act swiftly to mitigate the immediate risk. First, apply the latest patches for Chrome, Edge and any Chromium‑based browsers as soon as they become available. Second, prioritize updating Windows systems to the latest security baseline, especially those still on older builds that include the vulnerable kernel version. Proofpoint’s briefing suggests that even patched browsers may remain vulnerable until downstream releases catch up, so employing additional layers—such as application‑whitelisting, intrusion detection systems tuned for exploit‑chain signatures, and network segmentation—can buy critical time.

Finally, security teams should monitor for indicators of compromise associated with BlueMoon’s exploit chain. While the source material does not list specific IOCs, the high detection signals reported imply that existing security products may already flag anomalous activity linked to the kit. Continuous threat‑intel feeds and rapid patch‑management processes will be essential to stay ahead of this evolving threat.

Looking Ahead: The Future of Exploit Kits

BlueMoon serves as a stark reminder that the convergence of open‑source software, supply‑chain lag, and AI‑driven discovery can produce a “perfect storm” for cyber‑attackers. As Proofpoint notes, the kit’s rapid development and distribution across multiple actors suggest a lowering of barriers for sophisticated exploit creation. If AI continues to accelerate vulnerability discovery, we can expect more “weaponized” exploit chains targeting other critical platforms.

For defenders, the lesson is clear: patch management must become a race, not a routine. Organizations need to shorten the window between upstream fixes and downstream deployments, perhaps by adopting rapid‑release policies or leveraging browser‑level security features like sandboxing and site isolation. In an era where exploit kits can be shared across threat groups within days, the only viable defense is a proactive, layered approach that anticipates the next AI‑driven threat before it materializes.

This article was produced with AI-assisted research and editorial support. Reporting is based on the source material cited below. Sources: Ars Technica; arstechnica.com; Global1.News (10 September 2026).

By Jessica Ali, Staff Writer

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Jessica Ali

Editor-in-Chief at Global1.News. Atlanta-based journalist who cuts through the BS and tells it like it is. Lead anchor, host, and the voice you hear when the spin stops and the truth starts.

Comments (0)

User