INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Chrome Windows Zero-Day Exploit Chain Malware

| 2026-09-23 08:29 CRITICAL HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
The Chinese threat actors behind the recent exploitation of Google Chrome-Microsoft Windows zero-day vulnerability have been observed exploiting this weakness through fake websites masquerading as China Digital Times and Center for American Progress. These attacks, detected on September 3 and 4, involved chaining two vulnerabilities in Chrome and one impacting Windows Advanced Local Procedure Call to break out of the browser's sandbox and achieve remote code execution. The HTML element used by these attackers was said to have utilized a hard-coded domain named "[IOC HIDDEN • LOGIN REQUIRED]" for command-and-control over HTTP, indicating an attempt to mimic non-profit media outlet "theconversation.com". This suggests a coordinated effort within China's cyber community, where the core kit was likely shared and weaponized by multiple groups.
Technical Mitigations AI-generated
* Use up-to-date and patched versions of Chrome and Windows: Ensure that both your browser and operating system are running with the latest security patches, as these exploits were discovered after their initial release. * Implement robust anti-phishing measures: Use multi-factor authentication (MFA) for all accounts, enable two-factor authentication whenever possible, and be cautious when clicking on links or downloading attachments from unknown sources to prevent phishing attacks that could lead to fake websites masquerading as legitimate ones. * Keep software up-to-date with the latest security updates: Regularly update your operating system, browser, and other software to ensure you have the most recent security patches and fixes, which can help protect against known vulnerabilities like those exploited in this attack chain. * Use a reputable antivirus solution and keep it updated: Install and regularly update an anti-virus program that is designed to detect and remove malware, including CLEANGULP. This will help prevent infections from the exploit chain and other types of malware. * Be cautious when clicking on links or downloading attachments: Be wary of suspicious emails, messages, or downloads, as they may contain malicious code or links to phishing sites that could compromise your system's security.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

Ch•••••.exe
ch•••••.exe
ch•••••.exe
cm•••••.exe
am•••••.top
ch•••••.top
th•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowPadShadowPad CVE-2026-87491CVE-2026-87491 CVE-2026-85880CVE-2026-85880 CVE-2026-85046CVE-2026-85046
Target & Sectors
NORTH_AMERICA NORTH_AMERICA ASEAN ASEAN aerospaceaerospace defensedefense manufacturingmanufacturing mediamedia
Incident Timeline
‎September 3 and 4, 2026
Threat actors used exploit chains to target Windows and Chrome, exploiting vulnerabilities CVE-2026-85046 and CVE-2026-87491 in the browser's sandbox to achieve remote code execution.
infrastructure Windows
vulnerability CVE-2026-85046
vulnerability CVE-2026-87491
vulnerability CVE-2026-85880
tactic Remote Code Execution
organisation Windows Advanced Local Procedure Call
general_metric 85880 Windows Advanced Local Procedure Call
‎2025/09/15
Chrome's security updates from 2024 have been found to be vulnerable to exploitation by the SUPERSTOMP exploit chain.
‎November 2025
Threat actors used a zero-day vulnerability in the latest version of Chrome to gain unauthorized access.
‎March 2026
Threat actors used the same phishing sender address and hosting IP for their exploit infrastructure to target Chrome and Windows users.
tactic Phishing
organisation IP
‎June 2026
Threat actors used a zero-day vulnerability in the latest version of Chrome to gain unauthorized access.
‎August 4, 2026
The core Chrome flaw CVE-2026-85046 was reported to the Chromium project by a private researcher on August 4, 2026.
vulnerability CVE-2026-85046
organisation Chromium
‎August 6, 2026
Threat actors used a known exploit chain to target Chrome and Windows systems.
‎August 7
The fix for CVE-2026-85046 was committed to the Chromium source tree on August 7, approximately four weeks before it became available in stable Chrome.
vulnerability CVE-2026-85046
organisation Chromium
‎August 28, 2026
Threat actors used spear-phishing lures to target non-governmental organizations and mining companies in the U.S. with malicious links, tricking victims into clicking on a link that downloaded and installed BlueMoon via GhostChrome-X loader executable from Chrome extensions.
source_region China
attribution JungleBamboo
attribution PerplexedGoblin
attribution RedBravo
attribution Violet Typhoon
tactic Phishing
organisation Google Gemini
‎August 28
Researchers at enterprise cybersecurity company Proofpoint observed BlueMoon being used since August 28 in spearphishing operations attributed to the JungleBamboo threat actor associated with China.
source_region China
organisation JungleBamboo
organisation Violet Typhoon
tactic Phishing
target_region United States
organisation TA412
organisation the Association for Asian Studies
‎28 August 2026
Threat actors used the BlueMoon exploit kit to target Windows systems on 28 August 2026.
target_region China
organisation JungleBamboo
organisation Violet Typhoon
‎September 1, 2026
Two China-linked threat actors exploited a previously unknown vulnerability in Chrome/Windows, launching two separate espionage campaigns against non-government organizations.
infrastructure Windows
source_region China
organisation Volexity
‎September 1
Volexity detected a spear-phishing campaign by UTA0560 targeting several NGOs on September 1.
tactic Phishing
‎September 1st
Threat actors used exploit kits to compromise Chrome and Windows systems in espionage campaigns targeting NGOs.
‎September 2, 2026
Threat actors used spear-phishing lures to target a Vietnamese manufacturing entity, sending victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon.
tactic Phishing
target_region China
industry Aerospace
malware ShadowPad
organisation GemStone
target_region Viet Nam
industry Manufacturing
organisation Cloudflare Workers
organisation UNK_DoubleCheck (
‎September 2
China's UNK_LateNight group launched a second suspected cluster of exploit chains targeting US aerospace and defense companies with fake procurement inquiry emails.
source_region China
industry Aerospace
source_region United States
industry Defense
organisation RFQ
‎2026/09/02
Threat actors exploited CVE-2026-85880 in Microsoft's September 2026 Patch Tuesday updates to target systems running Windows.
vulnerability CVE-2026-85046
vulnerability CVE-2026-85880
organisation Microsoft
organisation Google
organisation CVE-2026
‎September 3, 2026
Threat actors used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore with landing pages that deployed BlueMoon.
industry Government
tactic Phishing
target_region China
target_region Indonesia
target_region Singapore
‎September 3
Threat actors used Google's patch for CVE-2026-85046 in the Stable Channel update on September 3 to target government, consulting, and financial organizations.
vulnerability CVE-2026-85046
infrastructure 152.0.7977
organisation Google
industry Government
target_region Indonesia
target_region Singapore
organisation Chromium
‎4 September
Threat actors exploited the September 4 Chrome vulnerability to target U.S. federal civilian agencies until September 18.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎September 8, 2026
Threat actors exploited a vulnerability in Chrome to target Windows systems by using an exploit chain.
‎2026/09/09
Threat actors used BlueMoon to target China.
source_region China
tactic Espionage
organisation BlueMoon
‎September 10, 2026
Four nation-state actors used the same Chrome zero-day exploit kit within 12 days.
infrastructure Windows
tactic Espionage
‎September 15, 2026
Threat actors used a known exploit in Windows to compromise systems.
infrastructure Windows
tactic Espionage
‎September 18
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 19.
attribution CISA
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎18 September
Threat actors exploited the September 4 Chrome vulnerability and launched two espionage campaigns targeting U.S. federal civilian agencies until September 18.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎Sep 23, 2026
Threat actors used a zero-day vulnerability in the latest version of Chrome to compromise compromised Windows systems, launching two separate espionage campaigns.
‎September 2026
Threat actors exploited CVE-2026-85880 in the Windows LPE component, while also targeting Chrome with an exploit chain.
infrastructure Windows
vulnerability CVE-2026-85880
organisation Microsoft
vulnerability CVE-2026-85046
organisation Google
organisation CVE-2026
‎2026/09/23
The exploit kit used in the incident targeted Chrome and Windows, with four distinct activity clusters associated with BlueMoon deployments.
organisation Google Chrome
infrastructure Windows
organisation China Digital Times
organisation CAP
organisation HTML
organisation SecurityAffairs
organisation ps
organisation UTA0565
organisation Google Chrome-Microsoft Windows
organisation Chrome/Windows
organisation Chrome
organisation Microsoft Windows
organisation Chromium
organisation WebAssembly
organisation Chrome’s
organisation ALPC
organisation Windows Notification Facility
organisation Windows Advanced Local Procedure Call
organisation DLL
organisation LPE
organisation Julia Paluch
organisation Stuart Del Caliz
organisation Mutex
organisation Dataupcheckinfo Registry
organisation CVE-2026-85046
organisation TurboFan
organisation Microsoft
organisation Rust
organisation GRIMWEDGE JScript
organisation GRIMWEDGE
organisation JScript
organisation UTA0560
organisation Google
organisation JungleBamboo
organisation Violet Typhoon
organisation TA412
organisation LONGTALE
organisation SUPERSTOMP
organisation Google Gemini
organisation GemStone
organisation HMAC
organisation Chrome, Edge, Brave
organisation Secure Preferences
organisation NFL
organisation CHANEL
organisation Nation-State Actors
organisation BlueMoon
organisation CVE
organisation Cloudflare Worker
organisation Cloudflare R2
organisation DNS
organisation TXT
organisation Cloudflare Workers
data_breach 3 September
organisation CreateProcess
organisation Cloudflare R2 Bucket
organisation VRP
organisation CTF
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎152.0.7977
Software Version
Metrics
data_breach
3
September