Trusted Design

Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days

概要

Four espionage-motivated threat actors have been observed deploying the BlueMoon exploit kit, which chains Chrome browser and Microsoft Windows vulnerabilities. The initial adopter was China-aligned TA412 on 28 August 2026, followed by several other suspected China-nexus groups within days. The exploit chain targets CVE-2026-85046 (Chromium V8 type-confusion), a V8 sandbox escape, and CVE-2026-85880 (Windows kernel LPE affecting older builds). Both V8 vulnerabilities were patch-gap zero-days, with fixes available in upstream Chromium but not yet deployed in stable releases. The rapid adoption by multiple actors and low operational security suggest rushed deployment ahead of anticipated patches. Evidence including extensive logging, verbose comments, and markdown references indicate potential AI-assisted development. BlueMoon's ease of adoption suggests further proliferation among espionage and financially motivated actors is likely.

Created: 2026-09-09

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る