INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Chrome Windows Zero-Day Exploit Chain Malware
| 2026-09-23 08:29 CRITICAL HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
The Chinese threat actors behind the recent exploitation of Google Chrome-Microsoft Windows zero-day vulnerability have been observed exploiting this weakness through fake websites masquerading as China Digital Times and Center for American Progress. These attacks, detected on September 3 and 4, involved chaining two vulnerabilities in Chrome and one impacting Windows Advanced Local Procedure Call to break out of the browser's sandbox and achieve remote code execution. The HTML element used by these attackers was said to have utilized a hard-coded domain named "[IOC HIDDEN • LOGIN REQUIRED]" for command-and-control over HTTP, indicating an attempt to mimic non-profit media outlet "theconversation.com". This suggests a coordinated effort within China's cyber community, where the core kit was likely shared and weaponized by multiple groups.
Technical Mitigations AI-generated
* Use up-to-date and patched versions of Chrome and Windows: Ensure that both your browser and operating system are running with the latest security patches, as these exploits were discovered after their initial release.
* Implement robust anti-phishing measures: Use multi-factor authentication (MFA) for all accounts, enable two-factor authentication whenever possible, and be cautious when clicking on links or downloading attachments from unknown sources to prevent phishing attacks that could lead to fake websites masquerading as legitimate ones.
* Keep software up-to-date with the latest security updates: Regularly update your operating system, browser, and other software to ensure you have the most recent security patches and fixes, which can help protect against known vulnerabilities like those exploited in this attack chain.
* Use a reputable antivirus solution and keep it updated: Install and regularly update an anti-virus program that is designed to detect and remove malware, including CLEANGULP. This will help prevent infections from the exploit chain and other types of malware.
* Be cautious when clicking on links or downloading attachments: Be wary of suspicious emails, messages, or downloads, as they may contain malicious code or links to phishing sites that could compromise your system's security.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
Ch•••••.exe
ch•••••.exe
ch•••••.exe
cm•••••.exe
am•••••.top
ch•••••.top
th•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowPadShadowPad
CVE-2026-87491CVE-2026-87491
CVE-2026-85880CVE-2026-85880
CVE-2026-85046CVE-2026-85046
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
ASEAN
ASEAN
aerospaceaerospace
defensedefense
manufacturingmanufacturing
mediamedia
Incident Timeline
September 3 and 4, 2026
Threat actors used exploit chains to target Windows and Chrome, exploiting vulnerabilities CVE-2026-85046 and CVE-2026-87491 in the browser's sandbox to achieve remote code execution.
Click on any entity below to view its context and source!
infrastructure
Windows
The attacks, detected on September 3 and 4, 2026, involved the
chaining
of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser's sandbox and achieve remote code execution.
vulnerability
CVE-2026-85046
The attacks, detected on September 3 and 4, 2026, involved the
chaining
of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser's sandbox and achieve remote code execution.
vulnerability
CVE-2026-87491
The attacks, detected on September 3 and 4, 2026, involved the
chaining
of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser's sandbox and achieve remote code execution.
vulnerability
CVE-2026-85880
The attacks, detected on September 3 and 4, 2026, involved the
chaining
of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser's sandbox and achieve remote code execution.
tactic
Remote Code Execution
The attacks, detected on September 3 and 4, 2026, involved the
chaining
of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser's sandbox and achieve remote code execution.
organisation
Windows Advanced Local Procedure Call
The attacks, detected on September 3 and 4, 2026, involved the
chaining
of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser's sandbox and achieve remote code execution.
general_metric
85880 Windows Advanced Local Procedure Call
The attacks, detected on September 3 and 4, 2026, involved the
chaining
of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser's sandbox and achieve remote code execution.
2025/09/15
Chrome's security updates from 2024 have been found to be vulnerable to exploitation by the SUPERSTOMP exploit chain.
November 2025
Threat actors used a zero-day vulnerability in the latest version of Chrome to gain unauthorized access.
March 2026
Threat actors used the same phishing sender address and hosting IP for their exploit infrastructure to target Chrome and Windows users.
Click on any entity below to view its context and source!
tactic
Phishing
UTA0560’s link to its March 2026 campaigns rests on three points: the same phishing sender address, the same hosting IP for its exploit infrastructure, and a per-host beacon naming scheme that mirrors what UTA0560 used six months earlier.
organisation
IP
UTA0560’s link to its March 2026 campaigns rests on three points: the same phishing sender address, the same hosting IP for its exploit infrastructure, and a per-host beacon naming scheme that mirrors what UTA0560 used six months earlier.
June 2026
Threat actors used a zero-day vulnerability in the latest version of Chrome to gain unauthorized access.
August 4, 2026
The core Chrome flaw CVE-2026-85046 was reported to the Chromium project by a private researcher on August 4, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85046
The core Chrome flaw, CVE-2026-85046, was reported to the Chromium project by a private researcher on August 4, 2026.
organisation
Chromium
The core Chrome flaw, CVE-2026-85046, was reported to the Chromium project by a private researcher on August 4, 2026.
August 6, 2026
Threat actors used a known exploit chain to target Chrome and Windows systems.
August 7
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, approximately four weeks before it became available in stable Chrome.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85046
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, almost four weeks before it rolled into the stable Chrome release on September 3.
organisation
Chromium
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, almost four weeks before it rolled into the stable Chrome release on September 3.
August 28, 2026
Threat actors used spear-phishing lures to target non-governmental organizations and mining companies in the U.S. with malicious links, tricking victims into clicking on a link that downloaded and installed BlueMoon via GhostChrome-X loader executable from Chrome extensions.
Click on any entity below to view its context and source!
source_region
China
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
attribution
JungleBamboo
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
attribution
PerplexedGoblin
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
attribution
RedBravo
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
attribution
Violet Typhoon
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as
APT31
(aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026.
tactic
Phishing
A brief description of the observed attack chains is as follows -
APT31
(Beginning on August 28, 2026), which used spear-phishing lures to target non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the U.S. to trick victims into clicking on a malicious link that serves BlueMoon, which then downloads and runs a loader executable responsible for installing a malicious browser add-on disguised as Google Gemini using a
Chrome extension integrity bypass technique
called
GhostChrome-X
.
organisation
Google Gemini
A brief description of the observed attack chains is as follows -
APT31
(Beginning on August 28, 2026), which used spear-phishing lures to target non-governmental organizations (NGOs), mining companies, and physical commodity trading firms in the U.S. to trick victims into clicking on a malicious link that serves BlueMoon, which then downloads and runs a loader executable responsible for installing a malicious browser add-on disguised as Google Gemini using a
Chrome extension integrity bypass technique
called
GhostChrome-X
.
August 28
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used since August 28 in spearphishing operations attributed to the JungleBamboo threat actor associated with China.
Click on any entity below to view its context and source!
source_region
China
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used since August 28 in spearphishing operations attributed to the JungleBamboo (a.k.a. APT31, Violet Typhoon, APT31, Tide Castle) threat actor associated with China.
organisation
JungleBamboo
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used since August 28 in spearphishing operations attributed to the JungleBamboo (a.k.a. APT31, Violet Typhoon, APT31, Tide Castle) threat actor associated with China.
organisation
Violet Typhoon
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used since August 28 in spearphishing operations attributed to the JungleBamboo (a.k.a. APT31, Violet Typhoon, APT31, Tide Castle) threat actor associated with China.
tactic
Phishing
Starting August 28, TA412 targeted US NGOs, mining companies, and physical commodity trading firms using phishing emails that posed as university students seeking internships or as outreach related to the Association for Asian Studies conference.
target_region
United States
Starting August 28, TA412 targeted US NGOs, mining companies, and physical commodity trading firms using phishing emails that posed as university students seeking internships or as outreach related to the Association for Asian Studies conference.
organisation
TA412
Starting August 28, TA412 targeted US NGOs, mining companies, and physical commodity trading firms using phishing emails that posed as university students seeking internships or as outreach related to the Association for Asian Studies conference.
organisation
the Association for Asian Studies
Starting August 28, TA412 targeted US NGOs, mining companies, and physical commodity trading firms using phishing emails that posed as university students seeking internships or as outreach related to the Association for Asian Studies conference.
28 August 2026
Threat actors used the BlueMoon exploit kit to target Windows systems on 28 August 2026.
Click on any entity below to view its context and source!
target_region
China
“The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026.
organisation
JungleBamboo
“The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026.
organisation
Violet Typhoon
“The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026.
September 1, 2026
Two China-linked threat actors exploited a previously unknown vulnerability in Chrome/Windows, launching two separate espionage campaigns against non-government organizations.
Click on any entity below to view its context and source!
infrastructure
Windows
Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail.
source_region
China
Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail.
organisation
Volexity
Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail.
September 1
Volexity detected a spear-phishing campaign by UTA0560 targeting several NGOs on September 1.
Click on any entity below to view its context and source!
tactic
Phishing
On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several NGOs.
September 1st
Threat actors used exploit kits to compromise Chrome and Windows systems in espionage campaigns targeting NGOs.
September 2, 2026
Threat actors used spear-phishing lures to target a Vietnamese manufacturing entity, sending victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon.
Click on any entity below to view its context and source!
tactic
Phishing
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
target_region
China
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
industry
Aerospace
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
malware
ShadowPad
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
organisation
GemStone
The extension is a browser-surveillance and credential-theft backdoor dubbed
GemStone
that allows the threat actor to issue commands through a command-and-control (C2) channel.
UNK_LateNight
(Beginning on September 2, 2026), a China-aligned threat cluster which used spear-phishing lures to target multiple U.S. aerospace companies and lead victims to malicious links that deploy BlueMoon and the
ShadowPad
backdoor using DLL sideloading.
target_region
Viet Nam
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
industry
Manufacturing
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
organisation
Cloudflare Workers
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
organisation
UNK_DoubleCheck
(
UNK_DoubleCheck
(Beginning on September 2, 2026), which used spear-phishing lures to target a Vietnamese manufacturing entity to send victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon, which is then used to initiate a DLL sideloading attack to drop a Rust binary.
September 2
China's UNK_LateNight group launched a second suspected cluster of exploit chains targeting US aerospace and defense companies with fake procurement inquiry emails.
Click on any entity below to view its context and source!
source_region
China
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
industry
Aerospace
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
source_region
United States
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
industry
Defense
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
organisation
RFQ
On September 2, UNK_LateNight, a second suspected China-aligned cluster, began targeting US aerospace and defense companies with fake RFQ and procurement inquiry emails.
2026/09/02
Threat actors exploited CVE-2026-85880 in Microsoft's September 2026 Patch Tuesday updates to target systems running Windows.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85046
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
vulnerability
CVE-2026-85880
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
Microsoft
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
Google
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
CVE-2026
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
September 3, 2026
Threat actors used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore with landing pages that deployed BlueMoon.
Click on any entity below to view its context and source!
industry
Government
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
tactic
Phishing
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
target_region
China
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
target_region
Indonesia
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
target_region
Singapore
UNK_QuietRacket
(Beginning on September 3, 2026), a China-aligned threat actor that used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore to take victims to landing pages that deploy BlueMoon.
September 3
Threat actors used Google's patch for CVE-2026-85046 in the Stable Channel update on September 3 to target government, consulting, and financial organizations.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85046
Google patched
CVE-2026-85046
in the Stable Channel update on September 3, moving users to Chrome 152.0.7977.82 or .83, alongside eleven other fixes.
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, almost four weeks before it rolled into the stable Chrome release on September 3.
infrastructure
152.0.7977
Google patched
CVE-2026-85046
in the Stable Channel update on September 3, moving users to Chrome 152.0.7977.82 or .83, alongside eleven other fixes.
organisation
Google
Google patched
CVE-2026-85046
in the Stable Channel update on September 3, moving users to Chrome 152.0.7977.82 or .83, alongside eleven other fixes.
industry
Government
Since September 3, UNK_QuietRacket has targeted government, consulting, and financial organizations in Indonesia and Singapore with conference-themed lures.
target_region
Indonesia
Since September 3, UNK_QuietRacket has targeted government, consulting, and financial organizations in Indonesia and Singapore with conference-themed lures.
target_region
Singapore
Since September 3, UNK_QuietRacket has targeted government, consulting, and financial organizations in Indonesia and Singapore with conference-themed lures.
organisation
Chromium
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, almost four weeks before it rolled into the stable Chrome release on September 3.
4 September
Threat actors exploited the September 4 Chrome vulnerability to target U.S. federal civilian agencies until September 18.
Click on any entity below to view its context and source!
attribution
Known Exploited
"
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on 4 September, giving U.S. federal civilian agencies until 18 September to patch.
tactic
T1588.006 - Vulnerabilities
"
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on 4 September, giving U.S. federal civilian agencies until 18 September to patch.
September 8, 2026
Threat actors exploited a vulnerability in Chrome to target Windows systems by using an exploit chain.
2026/09/09
Threat actors used BlueMoon to target China.
Click on any entity below to view its context and source!
source_region
China
"Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus," Proofpoint
said
in a report published today.
tactic
Espionage
"Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus," Proofpoint
said
in a report published today.
organisation
BlueMoon
"Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus," Proofpoint
said
in a report published today.
September 10, 2026
Four nation-state actors used the same Chrome zero-day exploit kit within 12 days.
Click on any entity below to view its context and source!
infrastructure
Windows
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Pierluigi Paganini
September 10, 2026
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days.
tactic
Espionage
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Pierluigi Paganini
September 10, 2026
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days.
September 15, 2026
Threat actors used a known exploit in Windows to compromise systems.
Click on any entity below to view its context and source!
infrastructure
Windows
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Pierluigi Paganini
September 15, 2026
tactic
Espionage
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Pierluigi Paganini
September 15, 2026
September 18
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 19.
Click on any entity below to view its context and source!
attribution
CISA
CISA added the flaw to its Known Exploited Vulnerabilities catalog the next day, with a September 18 deadline for federal systems to remediate.
attribution
Known Exploited
CISA added the flaw to its Known Exploited Vulnerabilities catalog the next day, with a September 18 deadline for federal systems to remediate.
tactic
T1588.006 - Vulnerabilities
CISA added the flaw to its Known Exploited Vulnerabilities catalog the next day, with a September 18 deadline for federal systems to remediate.
18 September
Threat actors exploited the September 4 Chrome vulnerability and launched two espionage campaigns targeting U.S. federal civilian agencies until September 18.
Click on any entity below to view its context and source!
attribution
Known Exploited
"
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on 4 September, giving U.S. federal civilian agencies until 18 September to patch.
tactic
T1588.006 - Vulnerabilities
"
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on 4 September, giving U.S. federal civilian agencies until 18 September to patch.
Sep 23, 2026
Threat actors used a zero-day vulnerability in the latest version of Chrome to compromise compromised Windows systems, launching two separate espionage campaigns.
September 2026
Threat actors exploited CVE-2026-85880 in the Windows LPE component, while also targeting Chrome with an exploit chain.
Click on any entity below to view its context and source!
infrastructure
Windows
CVE-2026-85880, the Windows LPE component of the chain, is the same vulnerability Microsoft patched as an actively exploited zero-day in September 2026 Patch Tuesday.
vulnerability
CVE-2026-85880
CVE-2026-85880, the Windows LPE component of the chain, is the same vulnerability Microsoft patched as an actively exploited zero-day in September 2026 Patch Tuesday.
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
Microsoft
CVE-2026-85880, the Windows LPE component of the chain, is the same vulnerability Microsoft patched as an actively exploited zero-day in September 2026 Patch Tuesday.
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
vulnerability
CVE-2026-85046
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
Google
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
organisation
CVE-2026
While CVE-2026-85046 was patched by Google last week, CVE-2026-85880 was addressed by Microsoft as part of its September 2026 Patch Tuesday updates.
2026/09/23
The exploit kit used in the incident targeted Chrome and Windows, with four distinct activity clusters associated with BlueMoon deployments.
Click on any entity below to view its context and source!
organisation
Google Chrome
Google Chrome itself, though, hadn’t shipped that fix yet when the phishing started.
” This created an unusual patch gap: The vulnerability was known and fixed upstream, making it an N-day at the Chromium source level, but there was no patch release for Google Chrome users.” continues the report.
"
The exploit chain employs three vulnerabilities -
CVE-2026-85046
, a type confusion in V8 in Google Chrome
A V8 sandbox escape that does not have an assigned CVE identifier
CVE-2026-85880
, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC)
infrastructure
Windows
Attack chains making use of BlueMoon have been found to rely on phishing emails as a starting point to trick targets into visiting an actor-controlled URL that triggers the two V8 flaws in succession to achieve code execution and escape the browser sandbox, and then exploit the Windows local privilege escalation bug to inject shellcode that downloads multiple payloads depending on the threat cluster behind it.
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware.
Ravie Lakshmanan
Sep 23, 2026
Zero-Day / Vulnerability
A Chinese threat actor codenamed
UTA0565
has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each.
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire.
It then exploits a third vulnerability in the Windows kernel (
CVE-2026-85880
) to escape Chrome’s sandboxed renderer process and inject code into the Chrome browser process.”
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
BlueMoon combines two security issues in Chromium-based browsers that allow remote code execution and sandbox escape with a kernel local privilege escalation in Windows.
The three flaws chained by the BlueMoon exploit kit are:
CVE-2026-85046
: a type-confusion flaw in Chrome’s V8 JavaScript engine that provides arbitrary memory access inside the V8 sandbox
CVE-2026-87491
: a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode
CVE-2026-85880
: a heap-based buffer overflow in Windows ALPC that allows local privilege escalation
Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it has been leveraged since 2025 and repackaged in BlueMoon.
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws.
“This - combined with the exploit targeting older Windows builds - suggests that the exploit creator repackaged an existing capability into the BlueMoon exploit kit.”
It fingerprints the system, exploits the Windows privilege elevation flaw to elevate the Chrome renderer, and injects into Chrome’s parent process to run an operator-selected command.
“Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities.
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use.
The kit includes a complete Chrome exploit chain that can escape the V8 sandbox and gain higher privileges on Windows.
The Windows LPE only targets older builds, including Windows 10 through 22H2, Windows Server 2019 and 2022, and Windows 11 21H2.
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called
BlueMoon
that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week.
"
The exploit chain employs three vulnerabilities -
CVE-2026-85046
, a type confusion in V8 in Google Chrome
A V8 sandbox escape that does not have an assigned CVE identifier
CVE-2026-85880
, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC)
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
Process tree
: chrome.exe starting cmd.exe, then curl.exe, then msgbox.exe
File
: ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder
Folder
: C:\Users\Public\stomp_ext
Scheduled task
: EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup or GeForceService
Mutex
: Dataupcheckinfo
Registry key
: HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32
Proofpoint also published detection rules for the kit's JavaScript loader and its command-and-control traffic, numbered 2071919 through 2071924.
organisation
China Digital Times
These messages contained spoofed links pointing to "chinadigitaltimes[.]top" and "americanprgoress[.]top," which replicated the look of China Digital Times and CAP, while loading an additional HTML element via a hidden iframe.
organisation
CAP
These messages contained spoofed links pointing to "chinadigitaltimes[.]top" and "americanprgoress[.]top," which replicated the look of China Digital Times and CAP, while loading an additional HTML element via a hidden iframe.
organisation
HTML
These messages contained spoofed links pointing to "chinadigitaltimes[.]top" and "americanprgoress[.]top," which replicated the look of China Digital Times and CAP, while loading an additional HTML element via a hidden iframe.
organisation
SecurityAffairs
“The majority of observed BlueMoon usage is assessed to be China-aligned espionage-motivated activity, although there is not sufficient evidence to attribute BlueMoon usage exclusively to China-aligned threat actors at the time of writing.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, BlueMoon)
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Chrome)
organisation
ps
It supports the following capabilities -
shell, to run a command
ps, to list running processes
upload, to upload a file
download, to download a file
bof, to execute a Execution of a beacon object file (
BOF
)
Interestingly, CLEANGULP has been found to use a hard-coded domain named "thecovnresation[.]com" for command-and-control (C2) over HTTP, indicating an attempt to mimic "
theconversation[.]com
," a non-profit media outlet known for publishing academic research, analysis, and commentary.
organisation
UTA0565
Ravie Lakshmanan
Sep 23, 2026
Zero-Day / Vulnerability
A Chinese threat actor codenamed
UTA0565
has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.
organisation
Google Chrome-Microsoft Windows
Ravie Lakshmanan
Sep 23, 2026
Zero-Day / Vulnerability
A Chinese threat actor codenamed
UTA0565
has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.
organisation
Chrome/Windows
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each.
organisation
Chrome
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each.
It fingerprints the system, exploits the Windows privilege elevation flaw to elevate the Chrome renderer, and injects into Chrome’s parent process to run an operator-selected command.
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
Interestingly, both V8 vulnerabilities in Chrome are said to have been "patch-gap" zero-days at the time they were maliciously exploited.
organisation
Microsoft Windows
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
“Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities.
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called
BlueMoon
that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
organisation
Chromium
BlueMoon combines two security issues in Chromium-based browsers that allow remote code execution and sandbox escape with a kernel local privilege escalation in Windows.
"Given its ease of adoption, it is likely to proliferate further and be adopted by espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers.
organisation
WebAssembly
The three flaws chained by the BlueMoon exploit kit are:
CVE-2026-85046
: a type-confusion flaw in Chrome’s V8 JavaScript engine that provides arbitrary memory access inside the V8 sandbox
CVE-2026-87491
: a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode
CVE-2026-85880
: a heap-based buffer overflow in Windows ALPC that allows local privilege escalation
Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it has been leveraged since 2025 and repackaged in BlueMoon.
“The exploit first gains arbitrary read/write within the V8 sandbox through the Type confusion vulnerability (CVE-2026-85046), then combines a separate WebAssembly defect to escape the V8 sandbox (
CVE-2026-87491
).
then overwrites WebAssembly compiled function bodies with attacker shellcode from memory.
organisation
Chrome’s
The three flaws chained by the BlueMoon exploit kit are:
CVE-2026-85046
: a type-confusion flaw in Chrome’s V8 JavaScript engine that provides arbitrary memory access inside the V8 sandbox
CVE-2026-87491
: a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode
CVE-2026-85880
: a heap-based buffer overflow in Windows ALPC that allows local privilege escalation
Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it has been leveraged since 2025 and repackaged in BlueMoon.
CVE-2026-85046
is a type-confusion bug in Chrome’s V8 JavaScript engine that abuses an optimization flaw in the TurboFan JIT compiler: by mutating an array mid-sort, an attacker gets the ability to read object memory addresses and forge fake object pointers, building toward arbitrary read and write inside V8’s heap.
organisation
ALPC
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
organisation
Windows Notification Facility
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
organisation
Windows Advanced Local Procedure Call
"
The exploit chain employs three vulnerabilities -
CVE-2026-85046
, a type confusion in V8 in Google Chrome
A V8 sandbox escape that does not have an assigned CVE identifier
CVE-2026-85880
, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC)
organisation
DLL
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
The payload was
ShadowPad
, the modular backdoor extensively used by Chinese state groups, delivered through a DLL sideloading chain that creates a scheduled task named “EdgeCore_AutoUpdate” for persistence and unhooks 20 network monitoring functions to reduce visibility.
organisation
LPE
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
organisation
Julia Paluch
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
organisation
Stuart Del Caliz
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
organisation
Mutex
Process tree
: chrome.exe starting cmd.exe, then curl.exe, then msgbox.exe
File
: ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder
Folder
: C:\Users\Public\stomp_ext
Scheduled task
: EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup or GeForceService
Mutex
: Dataupcheckinfo
Registry key
: HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32
Proofpoint also published detection rules for the kit's JavaScript loader and its command-and-control traffic, numbered 2071919 through 2071924.
organisation
Dataupcheckinfo
Registry
Process tree
: chrome.exe starting cmd.exe, then curl.exe, then msgbox.exe
File
: ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder
Folder
: C:\Users\Public\stomp_ext
Scheduled task
: EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup or GeForceService
Mutex
: Dataupcheckinfo
Registry key
: HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32
Proofpoint also published detection rules for the kit's JavaScript loader and its command-and-control traffic, numbered 2071919 through 2071924.
organisation
CVE-2026-85046
The HTML element ("config.html") is said to have used the same
BlueMoon
exploit kit combining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, with the final "pp" shellcode downloading an executable named "chrome_cleanup.exe" from the bogus domain.
organisation
TurboFan
CVE-2026-85046
is a type-confusion bug in Chrome’s V8 JavaScript engine that abuses an optimization flaw in the TurboFan JIT compiler: by mutating an array mid-sort, an attacker gets the ability to read object memory addresses and forge fake object pointers, building toward arbitrary read and write inside V8’s heap.
organisation
Microsoft
The payload is a malware family dubbed CLEANGULP, which is built using the Microsoft Visual C Compiler.
organisation
Rust
A fourth group, tracked as UNK_DoubleCheck, targeted Vietnamese manufacturing firms with an in-memory Rust loader, though the final payload couldn’t be retrieved for analysis.
organisation
GRIMWEDGE JScript
Volexity observed two distinct clusters of activity using the exploit chain to deliver different payloads:
UTA0560 downloaded and deployed the GRIMWEDGE JScript backdoor providing host reconnaissance, file and process management, command execution, and payload delivery capabilities.
organisation
GRIMWEDGE
The second hacker group is UTA0560, which targeted NGOs using donation lures and triggered an infection chain that delivered Grimwedge, an in-memory JScript backdoor for reconnaissance, file and process management, command execution, and payload uploads.
UTA0560 used its access to drop a custom loader chain ending in GRIMWEDGE, a JScript backdoor running entirely in memory inside msiexec.exe.
organisation
JScript
The second hacker group is UTA0560, which targeted NGOs using donation lures and triggered an infection chain that delivered Grimwedge, an in-memory JScript backdoor for reconnaissance, file and process management, command execution, and payload uploads.
UTA0560 used its access to drop a custom loader chain ending in GRIMWEDGE, a JScript backdoor running entirely in memory inside msiexec.exe.
organisation
UTA0560
The second hacker group is UTA0560, which targeted NGOs using donation lures and triggered an infection chain that delivered Grimwedge, an in-memory JScript backdoor for reconnaissance, file and process management, command execution, and payload uploads.
organisation
Google
The kit repeatedly mentions Google’s V8CTF vulnerability bounty program.
organisation
JungleBamboo
Volexity later found
JungleBamboo
(also known as
APT31
,
Violet Typhoon
, or TA412) using the same exploit chain against different targets.
organisation
Violet Typhoon
Volexity later found
JungleBamboo
(also known as
APT31
,
Violet Typhoon
, or TA412) using the same exploit chain against different targets.
organisation
TA412
Volexity later found
JungleBamboo
(also known as
APT31
,
Violet Typhoon
, or TA412) using the same exploit chain against different targets.
organisation
LONGTALE
JungleBamboo deployed SUPERSTOMP, a loader that installed the LONGTALE credential-stealing Chrome extension.”
Victims only saw an image of a donation form made to look like it belonged to the targeted organization.
organisation
SUPERSTOMP
It deployed a loader Volexity calls SUPERSTOMP, which installs a malicious Chrome extension named LONGTALE.
organisation
Google Gemini
The extension masquerades as a Google Gemini assistant and logs every keystroke, steals cookies and session tokens, and takes screenshots when it spots keywords supplied by its command server.
TA412’s post-exploitation payload was GemStone, a malicious browser extension that masquerades as an “AI-powered browsing companion by Google Gemini.”
organisation
GemStone
TA412’s post-exploitation payload was GemStone, a malicious browser extension that masquerades as an “AI-powered browsing companion by Google Gemini.”
organisation
HMAC
SUPERSTOMP still gets through, by stripping the new hashes, forging the older legacy HMAC values Chrome still accepts as a fallback, and letting Chrome’s own migration logic re-authenticate the tampered profile as legitimate.
It installs into Chrome, Edge, Brave, and Vivaldi by bypassing the browser’s Secure Preferences protection mechanism using the same HMAC computation method the browser itself uses to validate extensions.
organisation
Chrome, Edge, Brave
It installs into Chrome, Edge, Brave, and Vivaldi by bypassing the browser’s Secure Preferences protection mechanism using the same HMAC computation method the browser itself uses to validate extensions.
organisation
Secure Preferences
It installs into Chrome, Edge, Brave, and Vivaldi by bypassing the browser’s Secure Preferences protection mechanism using the same HMAC computation method the browser itself uses to validate extensions.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Nation-State Actors
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days.
organisation
BlueMoon
Proofpoint is tracking the exploit kit used in this activity as BlueMoon.”
organisation
CVE
A V8 sandbox escape (no CVE assigned, Chrome doesn’t issue CVEs for sandbox escapes)
organisation
Cloudflare Worker
It runs its C2 through a Cloudflare Worker domain.
organisation
Cloudflare R2
Its payload downloaded a Rust-based loader from Cloudflare R2 that staged a second DLL sideloading chain for C2.
organisation
DNS
Its C2 uses Google’s DNS-over-HTTPS service to resolve addresses through TXT records, then decrypts them with ChaCha20 before reaching Cloudflare Workers.
organisation
TXT
Its C2 uses Google’s DNS-over-HTTPS service to resolve addresses through TXT records, then decrypts them with ChaCha20 before reaching Cloudflare Workers.
organisation
Cloudflare Workers
Its C2 uses Google’s DNS-over-HTTPS service to resolve addresses through TXT records, then decrypts them with ChaCha20 before reaching Cloudflare Workers.
data_breach
3 September
This suggests the developers focused on releasing the exploit before the September 3 Chrome patch rather than making it difficult to detect.
organisation
CreateProcess
With those additional privileges, a separate injector shellcode injects a CreateProcess stub into the parent Chrome broker process, executing an operator-specified command.
organisation
Cloudflare R2 Bucket
The malware, for its part, contacts a Cloudflare R2 Bucket to fetch and execute a second DLL sideloading pair.
organisation
VRP
This is also bolstered by repeated references to the
v8CTF
challenge, an exploit-focused vulnerability reward program (VRP) and capture-the-flag (CTF) competition run by Google targeting the V8 engine.
organisation
CTF
This is also bolstered by repeated references to the
v8CTF
challenge, an exploit-focused vulnerability reward program (VRP) and capture-the-flag (CTF) competition run by Google targeting the V8 engine.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware.
Ravie Lakshmanan
Sep 23, 2026
Zero-Day / Vulnerability
A Chinese threat actor codenamed
UTA0565
has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.
The attacks, detected on September 3 and 4, 2026, involved the
chaining
of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break out of the browser's sandbox and achieve remote code execution.
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each.
Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail.
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire.
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Pierluigi Paganini
September 15, 2026
It then exploits a third vulnerability in the Windows kernel (
CVE-2026-85880
) to escape Chrome’s sandboxed renderer process and inject code into the Chrome browser process.”
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
BlueMoon combines two security issues in Chromium-based browsers that allow remote code execution and sandbox escape with a kernel local privilege escalation in Windows.
The three flaws chained by the BlueMoon exploit kit are:
CVE-2026-85046
: a type-confusion flaw in Chrome’s V8 JavaScript engine that provides arbitrary memory access inside the V8 sandbox
CVE-2026-87491
: a V8 sandbox escape that corrupts WebAssembly metadata to run embedded shellcode
CVE-2026-85880
: a heap-based buffer overflow in Windows ALPC that allows local privilege escalation
Proofpoint says attackers exploited CVE-2026-85880 as a classic zero-day, suspecting it has been leveraged since 2025 and repackaged in BlueMoon.
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws.
“This - combined with the exploit targeting older Windows builds - suggests that the exploit creator repackaged an existing capability into the BlueMoon exploit kit.”
It fingerprints the system, exploits the Windows privilege elevation flaw to elevate the Chrome renderer, and injects into Chrome’s parent process to run an operator-selected command.
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Pierluigi Paganini
September 10, 2026
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days.
“Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities.
CVE-2026-85880
, a Windows kernel local privilege escalation using ALPC and Windows Notification Facility mechanisms, completes the chain and elevates the attacker from the browser’s sandboxed renderer to a position where they can inject code into Chrome’s parent process and run arbitrary commands.
Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use.
The kit includes a complete Chrome exploit chain that can escape the V8 sandbox and gain higher privileges on Windows.
CVE-2026-85880, the Windows LPE component of the chain, is the same vulnerability Microsoft patched as an actively exploited zero-day in September 2026 Patch Tuesday.
The Windows LPE only targets older builds, including Windows 10 through 22H2, Windows Server 2019 and 2022, and Windows 11 21H2.
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called
BlueMoon
that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
Attack chains making use of BlueMoon have been found to rely on phishing emails as a starting point to trick targets into visiting an actor-controlled URL that triggers the two V8 flaws in succession to achieve code execution and escape the browser sandbox, and then exploit the Windows local privilege escalation bug to inject shellcode that downloads multiple payloads depending on the threat cluster behind it.
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week.
"
The exploit chain employs three vulnerabilities -
CVE-2026-85046
, a type confusion in V8 in Google Chrome
A V8 sandbox escape that does not have an assigned CVE identifier
CVE-2026-85880
, a heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC)
"Following the Chrome exploits, the kit uses a reflectively loaded DLL to fingerprint the Windows host, which the exploit kit JavaScript uses to decide whether to attempt the LPE exploit," Proofpoint researchers Mark Kelly, Greg Lesnewich, Konstantin Klinger, Saher Naumaan, Julia Paluch, David Galazin, and Stuart Del Caliz said.
Process tree
: chrome.exe starting cmd.exe, then curl.exe, then msgbox.exe
File
: ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder
Folder
: C:\Users\Public\stomp_ext
Scheduled task
: EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup or GeForceService
Mutex
: Dataupcheckinfo
Registry key
: HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32
Proofpoint also published detection rules for the kit's JavaScript loader and its command-and-control traffic, numbered 2071919 through 2071924.
Metrics
infrastructure
152.0.7977
Software Version
Google patched
CVE-2026-85046
in the Stable Channel update on September 3, moving users to Chrome 152.0.7977.82 or .83, alongside eleven other fixes.
Metrics
data_breach
3
September
This suggests the developers focused on releasing the exploit before the September 3 Chrome patch rather than making it difficult to detect.
Intelligence Sources
Security Affairs
2026-09-10
Security Affairs
2026-09-15
BleepingComputer
2026-09-10
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
BleepingComputer
The Hacker News
2026-09-09
The Hacker News
2026-09-23
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-23T10:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
62x
organisation
Identified Entity
China Digital Times
entity
34x
timeline
Temporal Reference
Sep 23, 2026
date
14x
attribution
Attributing Entity
the Center for American Progress
authority
6x
target region
Target Country
Hong Kong
country
6x
tactic
Cyber Operation Type
Phishing
tactic
5x
industry
Targeted Sector
Government
sector
5x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
3x
vulnerability
Exploited CVE
CVE-2026-85046
cve
2x
source region
Origin Country
China
country
Contextual Telemetry
Context Block
13 METRICS
infrastructure
Affected Product
Windows
software
general metric
Sep
23
sep
general metric
Windows Advanced Local Procedure Call
85,880
windows advanced local procedure call
malware
Malware Payload
ShadowPad
tool
general metric
Confusion Vulnerability
85,046
confusion vulnerability
infrastructure
Software Version
152.0.7977
version
general metric
Url Parameters
13
url parameters
general metric
Lines
250
lines
general metric
Entities
1
entities
general metric
Cve-2026
87,491
cve-2026
general metric
Windows
10
windows
general metric
Network
20
network
data breach
September
3
september
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.