Multiple Espionage Groups Exploit Chrome and Windows Vulnerabilities via BlueMoon Kit
Multiple espionage groups exploited a previously undocumented Chrome and Windows exploit kit called BlueMoon, leveraging three vulnerabilities (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to execute code, escape sandboxes, and escalate privileges. The exploit kit's rapid adoption by at least four threat clusters, including China-aligned actors, highlights growing risks from AI-assisted exploit development and delayed patch propagation in Chromium-based browsers.
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
*** END OF TRANSMISSION ***