Desk live·
ForensicPost
Nation-state/Exploitation/File 26-0909

Four China-Aligned Clusters Used the Same Chrome and Windows Zero-Day Chain Within a Week

Proofpoint’s BlueMoon report describes near-identical exploit code, down to variable names and comments, in the hands of APT31 and three unnamed clusters, against U.S. NGOs, defence contractors and Southeast Asian governments. The patch gap was the window, and Google has moved Chrome to a two-week cycle.

Constructed geometry · not a chart of case data
TargetNGOs, defence contractors, SE Asian governments
ActorAPT31 and China-aligned clusters (vendor)
D. Kennedy10 min readConfidence: medium4 sources reviewed

Proofpoint reported on 9 September 2026 that an exploit chain it calls BlueMoon, combining a Chrome V8 type confusion (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491) and a Windows kernel privilege escalation (CVE-2026-85880), had been used by at least four separate espionage clusters between 28 August and 3 September. The first was TA412, which Proofpoint equates with APT31, against U.S. NGOs and commodity-trading firms. Three clusters it tracks as UNK_LateNight, UNK_QuietRacket and UNK_DoubleCheck followed within days against the U.S. defence industrial base, government and finance entities in Indonesia and Singapore, and a Vietnamese manufacturer.

The V8 bug had been fixed upstream in Chromium around 7 August. Chrome’s stable patch shipped on 3 September, and the second V8 fix on 8 September. The clusters were exploiting a flaw that was already public in the open-source tree and not yet in the browser most people run. CISA added the Chrome and Windows bugs to its exploited-vulnerabilities catalogue on 4 and 8 September. Volexity separately reported a fifth cluster using the chain against NGOs from 1 September, delivered through a cross-site scripting flaw on a U.S. university’s website.

Identical Code, Different Hands

Proofpoint’s Mark Kelly told The Record the exploit code across clusters was practically identical, including variable naming and commentary. The payloads differed: a malicious Chrome extension posing as Google Gemini that logs keystrokes and steals sessions for TA412, ShadowPad for the cluster targeting defence firms, a Rust loader and a .NET implant with DNS-over-HTTPS command channels elsewhere. One kit, several operators, each with their own tooling on top. Whether that describes a shared supplier, a shared parent or a shared leak, the report does not say.

What The Record Allows

The attribution here is vendor cluster naming. APT31’s members were indicted by the U.S. in 2024 as contractors for a Chinese state security department, which is historic government attribution of the actor, not of this campaign. The three UNK_ clusters are suspected China-aligned on Proofpoint’s assessment. No government has attributed BlueMoon. The corpus files a vendor cluster name as a claim, and this file carries four of them. Proofpoint also noted artefacts in the exploit, diagnostic logging and a handover document, consistent with possible AI-assisted development, and stopped short of concluding it.

The Window

The operational fact is the patch gap: the period between a fix landing in an open-source repository and reaching the shipped product. For a browser it is measured in weeks, and this campaign shows what an organised adversary does with weeks. Google’s response, reported by The Record, was to move Chrome to a two-week release cycle. The corpus filed the edge-device version of the same race at 26-0810b; this is the endpoint version.

How we reported this

Compiled from Proofpoint’s report, Volexity’s research as reported and contemporaneous coverage, listed below. Cluster names and China-alignment assessments are the vendors’ and are stated as such; no government attribution exists for this campaign. Compromised-organisation counts were not published. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel ExploitProofpoint
  2. Multiple Chinese hacking groups seen using identical Chrome zero-dayThe Record
  3. China-Linked Hackers Exploit Chrome-Windows Zero-Day ChainThe Hacker News
  4. BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-DaysSecurityWeek
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary