Proofpoint reported on 9 September 2026 that an exploit chain it calls BlueMoon, combining a Chrome V8 type confusion (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491) and a Windows kernel privilege escalation (CVE-2026-85880), had been used by at least four separate espionage clusters between 28 August and 3 September. The first was TA412, which Proofpoint equates with APT31, against U.S. NGOs and commodity-trading firms. Three clusters it tracks as UNK_LateNight, UNK_QuietRacket and UNK_DoubleCheck followed within days against the U.S. defence industrial base, government and finance entities in Indonesia and Singapore, and a Vietnamese manufacturer.
The V8 bug had been fixed upstream in Chromium around 7 August. Chrome’s stable patch shipped on 3 September, and the second V8 fix on 8 September. The clusters were exploiting a flaw that was already public in the open-source tree and not yet in the browser most people run. CISA added the Chrome and Windows bugs to its exploited-vulnerabilities catalogue on 4 and 8 September. Volexity separately reported a fifth cluster using the chain against NGOs from 1 September, delivered through a cross-site scripting flaw on a U.S. university’s website.
Identical Code, Different Hands
Proofpoint’s Mark Kelly told The Record the exploit code across clusters was practically identical, including variable naming and commentary. The payloads differed: a malicious Chrome extension posing as Google Gemini that logs keystrokes and steals sessions for TA412, ShadowPad for the cluster targeting defence firms, a Rust loader and a .NET implant with DNS-over-HTTPS command channels elsewhere. One kit, several operators, each with their own tooling on top. Whether that describes a shared supplier, a shared parent or a shared leak, the report does not say.
What The Record Allows
The attribution here is vendor cluster naming. APT31’s members were indicted by the U.S. in 2024 as contractors for a Chinese state security department, which is historic government attribution of the actor, not of this campaign. The three UNK_ clusters are suspected China-aligned on Proofpoint’s assessment. No government has attributed BlueMoon. The corpus files a vendor cluster name as a claim, and this file carries four of them. Proofpoint also noted artefacts in the exploit, diagnostic logging and a handover document, consistent with possible AI-assisted development, and stopped short of concluding it.
The Window
The operational fact is the patch gap: the period between a fix landing in an open-source repository and reaching the shipped product. For a browser it is measured in weeks, and this campaign shows what an organised adversary does with weeks. Google’s response, reported by The Record, was to move Chrome to a two-week release cycle. The corpus filed the edge-device version of the same race at 26-0810b; this is the endpoint version.
Compiled from Proofpoint’s report, Volexity’s research as reported and contemporaneous coverage, listed below. Cluster names and China-alignment assessments are the vendors’ and are stated as such; no government attribution exists for this campaign. Compromised-organisation counts were not published. Graded medium. Corrections: corrections@forensicpost.com.
- Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel ExploitProofpoint
- Multiple Chinese hacking groups seen using identical Chrome zero-dayThe Record
- China-Linked Hackers Exploit Chrome-Windows Zero-Day ChainThe Hacker News
- BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-DaysSecurityWeek