Skip to content

Security1 publisher3 min readPublished

Four China-aligned crews adopted the same Chrome-to-SYSTEM exploit kit inside six days

Proofpoint says APT31 fired first on Aug. 28 and three more espionage groups were running the same three-bug BlueMoon chain by Sept. 3, which points at a shared exploit-kit supplier rather than four separate discoveries.

The Watch · Security desk

Illustration accompanying Four China-aligned crews adopted the same Chrome-to-SYSTEM exploit kit inside six days

What happened

  • Proofpoint says at least four state-aligned groups have chained three zero-days it calls BlueMoon for espionage against targets of interest to Beijing since late August.
  • TA412, also tracked as APT31 and Violet Typhoon, went first on Aug. 28, phishing US non-governmental organizations, mining companies and commodity trading firms.
  • Kelly says the chain runs code in the browser sandbox, escapes it, and takes system privileges on the target machine.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability Reading a public Chromium commit produced a live zero-day against shipped browsers, so the attacker's cheapest research path is now the vendor's own fix, not original bug hunting.
  • exposure Because Microsoft's ALPC fix only landed Tuesday, every organization running the vulnerable Chrome build through early September had a sandbox escape with no available patch behind it.
  • precedent Kelly expects the kit to reach financially motivated actors as patched browsers roll out, which puts a browser-to-SYSTEM chain in criminal hands against the slowest-updating estates.
  • contradiction The sub-20 victim count is what one vendor's telemetry saw, and Kelly's own caveat that the real figure is much higher means nobody currently has a defensible scope number to plan around.

Proofpoint's account centers on the word "kit." Mark Kelly, a staff threat researcher there, attributes the browser half of BlueMoon to a developer who likely reverse engineered publicly available Chromium patches to weaponize the chain [6]. Four groups running the same three bugs within six days [1], with only slight technical changes and different target sets between them [11], fits one quartermaster with four customers. Independent discovery of the identical trio inside that window is the harder claim.

The V8 pair had already been fixed in Chromium source and had not yet reached the latest public browser builds, which is why Kelly calls them effective zero-days in those products [5]. That inverts the usual race. The fix is readable before the binary is installable, and anyone tracking commits gets a working exploit against every user still on the old build. Activity peaked Sept. 2-3, immediately before the Chrome patch shipped, and Proofpoint saw BlueMoon in use as late as Sept. 8 [12] [13] - roughly five days of observed exploitation after the browser fix was out [2]. That tail reflects the rollout lag across Chromium-based browsers.

The third link had no fix at all for the duration. CVE-2026-85880, the privilege escalation in Windows Advanced Local Procedure Call, was disclosed by Microsoft on Tuesday [4], after the campaigns. So through late August and early September the escalation step was unpatchable, and the only lever a defender held was the browser update. Pulling it breaks the chain at the entry point, because the V8 remote-code-execution bugs are what deliver code into the sandbox in the first place [3] [2].

Scope is thin and Proofpoint says so: fewer than 20 organizations directly observed globally, with Kelly stating the true number is likely much higher [14]. The targeting is coherent across the four users. APT31 phished US non-governmental organizations, mining companies and commodity trading firms, dropping a malicious browser extension disguised as Google Gemini that surveils browsing, steals credentials and runs commands [8] [9]. UNK_LateNight hit US aerospace on Sept. 2, UNK_DoubleCheck hit Vietnamese manufacturers the same day using a compromised Southeast Asian government mailbox, and UNK_QuietRacket hit Indonesian and Singaporean government, consulting and financial targets on Sept. 3 [10]. Only a limited set of organizations was exposed to all three vulnerabilities at once, and delivery infrastructure was stood up the same day as each campaign or days before it [7], rushed and built to be thrown away.

Kelly expects the kit to proliferate to additional espionage-motivated and financially motivated actors as patched browser versions finish rolling out [15]. A browser-to-SYSTEM chain becomes commodity tooling at exactly the point espionage operators stop needing it.</body_markdown> </invoke>

What to watch

  • Whether Proofpoint or Google names a non-Chinese or financially motivated user of the BlueMoon kit, which is the proliferation Kelly forecast.
  • Whether any Chromium-based browser other than Chrome is still shipping the vulnerable V8 build, extending the exploitation tail.
  • Whether the directly observed victim count moves above 20 organizations, or CISA adds CVE-2026-85880 to its exploited-vulnerabilities catalog.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories