ThreatPaper
State-SponsoredMalwareHigh

BlueMoon: four state-aligned actors chain two patch-gap Chrome zero-days and a Windows LPE within 12 days

By Sethu Satheesh · 29 Sept 2026 · 11 min read

Threat Actor: TA412 (APT31 / Violet Typhoon, China-aligned) plus UNK_LateNight, UNK_QuietRacket, UNK_DoubleCheck · Target: US NGOs, mining, commodity trading, aerospace/defense; government, financial, consulting and manufacturing in Indonesia, Singapore, Vietnam

Source: www.proofpoint.com


Executive Summary

In late August and September 2026, Proofpoint documented BlueMoon, a novel exploit chain that four espionage-motivated, state-aligned threat clusters adopted within days of one another to compromise fully updated Windows machines through the browser.12 The chain links three vulnerabilities: CVE-2026-85046, a type-confusion remote-code-execution bug in Chrome's V8 engine; CVE-2026-87491, a V8 out-of-bounds write used to escape the renderer sandbox; and CVE-2026-85880, a heap-based buffer overflow in Windows ALPC for local privilege escalation.134 Together they take an attacker from a crafted web page to SYSTEM-level control on a patched machine.1

The defining detail is when the browser bugs were exploitable. Both V8 vulnerabilities were "patch-gap" zero-days: the fixes had already been committed to the public, upstream Chromium source code but had not yet rolled into the stable Chrome builds that users run. The fix for CVE-2026-85046 was committed upstream on August 7, 2026 but did not reach a general stable Chromium build until September 3 — a roughly four-week window in which anyone could reverse-engineer the public patch and exploit the still-unpatched stable browser.1 This is the open-source-security paradox in operation: the transparency that lets defenders review a fix also hands attackers a map to the vulnerability before most users receive it.

The first cluster to use BlueMoon was TA412 (also tracked as APT31 / Violet Typhoon), a China-aligned actor, first observed on August 28, 2026.1 Three further espionage clusters — UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket — began using the same chain between September 2 and 3.1 TA412's own campaign is instructive: it spearphished US NGOs, mining firms and commodity traders while posing as university students seeking internships and as organizers reaching out about the Association for Asian Studies "AAS-in-Asia 2026" conference; victims who clicked were taken to actor-controlled pages that ran the exploit behind a loading screen before redirecting to legitimate sites like GitHub and asianstudies.org.1 The post-exploitation payload is pointed: a malicious Chrome extension named GemStone, disguised as "Google Gemini," an AI browsing companion — a full browser-surveillance backdoor with keylogging, screen recording, cookie and credential theft, tab surveillance and remote command execution, installed by forging Chromium's Secure Preferences HMAC to bypass Web Store verification.1 The other clusters carried different payloads: ShadowPad (UNK_LateNight), a Rust-based loader with Cloudflare R2 command-and-control (UNK_DoubleCheck), and shellcode with ChaCha20-encrypted DNS-over-HTTPS C&C (UNK_QuietRacket).1

That four espionage actors picked up the same non-trivial exploit chain within about twelve days points less to four independent discoveries than to a shared source — a quartermaster or vendor distributing the kit — which is the strategically significant part: capability that would once have belonged to one well-resourced group is now being fielded across several at once, against NGOs, aerospace and defense, mining, and government and financial targets across the US and Asia.12

Verification of Claims

  1. Claim: A three-CVE exploit chain (BlueMoon) took attackers from a web page to Windows privilege escalation, using two patch-gap Chrome zero-days. → Verified → Proofpoint documents the chain (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880); NVD confirms the CVEs as a V8 type confusion RCE, a V8 out-of-bounds write, and a Windows ALPC heap overflow LPE. The CVE-2026-85046 fix was committed upstream on August 7 but did not reach stable Chromium until September 3.134

  2. Claim: Four Chinese state-sponsored groups used BlueMoon. → Assessed / partly imprecise → TA412 is a well-established China-aligned actor (APT31 / Violet Typhoon). The other three are espionage-motivated clusters Proofpoint tracks under UNK_ designations; UNK_DoubleCheck's attribution is explicitly unclear. The near-simultaneous adoption points to a shared supplier rather than four independently developed capabilities.1

  3. Claim: BlueMoon was developed with AI assistance. → Weak evidence → Proofpoint notes development artifacts left in the samples — verbose logging and comments, evidence of iterative debugging, references to markdown handover documentation and the v8CTF bug-bounty framework — but states that "no single artifact conclusively confirms" AI involvement. It is a plausible, hedged observation, not an established fact.1

  4. Claim: The GemStone extension installs without Chrome Web Store verification. → Verified → Proofpoint states the extension bypassed Chromium's Secure Preferences HMAC protection using publicly documented forgery techniques to install without Web Store verification.1

Timeline

Date Actor Event Source
August 7, 2026 Chromium project Fix for CVE-2026-85046 committed to upstream Chromium source (not yet in stable) 1
August 28, 2026 TA412 (APT31 / Violet Typhoon) First observed use of the BlueMoon chain against US NGOs, mining and commodity firms 1
September 2, 2026 UNK_LateNight, UNK_DoubleCheck Begin using BlueMoon (ShadowPad; Rust loader) 1
September 3, 2026 UNK_QuietRacket / Chromium UNK_QuietRacket begins using BlueMoon; the CVE-2026-85046 fix reaches a general stable Chromium build 1
September 3–9, 2026 NVD CVE-2026-85046 (Sep 3), CVE-2026-85880 (Sep 8) and CVE-2026-87491 (Sep 9) published 34
September 2026 Proofpoint Publishes the BlueMoon analysis 1

Attack Anatomy

TA412 approached victims with tailored lures — posing as students seeking internships and as organizers of the AAS-in-Asia 2026 conference — containing links to actor-controlled infrastructure (T1566.002).1

Browser exploitation — patch-gap V8 zero-days

The link led to a page that, behind a loading screen, ran the exploit before redirecting to a legitimate site. CVE-2026-85046 (V8 type confusion) achieved remote code execution inside the Chrome sandbox; CVE-2026-87491 (V8 out-of-bounds write) escaped the renderer sandbox by overwriting WebAssembly compiled function bodies with shellcode (T1203).13

Privilege escalation — Windows ALPC

CVE-2026-85880, a heap overflow in Windows ALPC, elevated privileges locally, completing the path from web page to system compromise on a range of Windows 10, 11 and Server builds (T1068).14

Post-exploitation — a "Google Gemini" surveillance extension and other payloads

TA412 installed GemStone, a malicious Chrome extension masquerading as "Google Gemini," forging Chromium's Secure Preferences HMAC to install it without Web Store verification (T1176.001).1 GemStone keylogs, records the screen, steals cookies and credentials, watches tabs, and executes remote commands via a Cloudflare Worker C&C (T1056.001, T1113, T1539, T1102).1 Other clusters delivered ShadowPad via DLL side-loading (UNK_LateNight), a Rust loader with Cloudflare R2 C&C (UNK_DoubleCheck), and shellcode with ChaCha20-encrypted DNS-over-HTTPS C&C (UNK_QuietRacket) (T1574.001, T1071.004).1

Loading diagram...

Threat Actor Profile

  • TA412 — also tracked as APT31 and Violet Typhoon; a long-running China-aligned espionage actor. First to field BlueMoon (Aug 28, 2026), targeting US NGOs, mining and commodity trading with the GemStone extension.1
  • UNK_LateNight — espionage cluster; adopted BlueMoon Sep 2; delivered ShadowPad via DLL side-loading against US aerospace and defense.1
  • UNK_QuietRacket — espionage cluster; adopted Sep 3; targeted government, consulting and financial sectors in Indonesia and Singapore with ChaCha20-encrypted DoH C&C.1
  • UNK_DoubleCheck — suspected espionage cluster (attribution unclear); adopted Sep 2; a Rust loader with Cloudflare R2 C&C against Vietnamese manufacturing.1
  • Attribution confidence: High for TA412 (established APT31); the UNK_ clusters are espionage-motivated with varying confidence, and UNK_DoubleCheck's attribution is explicitly unclear. The rapid, shared adoption of a single non-trivial chain across four actors points to a common supplier/quartermaster rather than parallel independent development.1
  • Notable: Proofpoint observed development artifacts (verbose logging, iterative-debugging traces, markdown handover docs, v8CTF references) consistent with — but not conclusive of — AI-assisted development, and noted the default configuration's noisy curl-based downloads suggest the operators prioritized speed of deployment over stealth.1

MITRE ATT&CK techniques (verified on attack.mitre.org):

ID Technique
T1566.002 Phishing: Spearphishing Link
T1203 Exploitation for Client Execution
T1068 Exploitation for Privilege Escalation
T1176.001 Software Extensions: Browser Extensions
T1056.001 Input Capture: Keylogging
T1113 Screen Capture
T1539 Steal Web Session Cookie
T1574.001 Hijack Execution Flow: DLL
T1071.004 Application Layer Protocol: DNS
T1102 Web Service

Technical Indicators

exploit_chain:
  - "CVE-2026-85046 — V8 type confusion RCE (Chrome < 152.0.7977.82); upstream fix 7 Aug, stable 3 Sep 2026 (patch-gap)"
  - "CVE-2026-87491 — V8 out-of-bounds write, sandbox escape (Chrome < 153.0.8010.36)"
  - "CVE-2026-85880 — Windows ALPC heap overflow, local privilege escalation"
affected_windows:
  - "Windows 10 1809/2004/20H2/21H1/21H2/22H2; Server 2019/2022; Windows 11 21H2"
ta412_payload:
  - "GemStone — malicious Chrome extension disguised as 'Google Gemini'"
  - "capabilities: keylogging, screen recording, cookie/credential theft, tab surveillance, remote command execution"
  - "permissions: cookies, storage, tabs, scripting, activeTab, downloads, webNavigation, alarms"
  - "install: forges Chromium Secure Preferences HMAC to bypass Web Store verification"
  - "C&C: Cloudflare Worker"
other_payloads:
  - "UNK_LateNight: ShadowPad via DLL side-loading, registry persistence"
  - "UNK_DoubleCheck: Rust loader, RC4 decryption, Cloudflare R2 C&C"
  - "UNK_QuietRacket: injection shellcode, ChaCha20-encrypted DNS-over-HTTPS C&C"
host_indicators:
  - "process tree: chrome.exe -> cmd.exe -> curl.exe -> msgbox.exe"
  - "session storage key: v8ctf_exp_attempt"
  - "scheduled tasks: EdgeCore_AutoUpdate, GeForceService"
note: >
  Full IOC and detection detail is in Proofpoint's report. Redirect
  destinations shown to victims post-exploit included legitimate sites
  (GitHub, asianstudies.org) and are not themselves malicious.

No law-enforcement action or government advisory specific to BlueMoon had been published as of this writing; the disclosure is vendor threat research by Proofpoint.1 The most important remediation is patching: Chrome/Chromium users needed the stable builds that closed CVE-2026-85046 (152.0.7977.82) and CVE-2026-87491 (153.0.8010.36), and Windows systems needed the fix for the ALPC LPE (CVE-2026-85880).34 Because two of the three were patch-gap zero-days, the exposure window predates the public CVE dates for users on stable channels.1

Impact Assessment

  • Confirmed (per Proofpoint): Four espionage clusters used the BlueMoon chain between Aug 28 and Sep 3, 2026, achieving browser-to-system compromise on patched Windows machines via two patch-gap V8 zero-days and a Windows ALPC LPE.1
  • Confirmed: TA412 deployed the GemStone "Google Gemini" surveillance extension against US NGOs, mining and commodity firms; other clusters used ShadowPad, a Rust loader, and shellcode against US aerospace/defense and Asian government, financial, consulting and manufacturing targets.1
  • Assessed: A shared supplier/quartermaster is the likely explanation for the near-simultaneous adoption; UNK_DoubleCheck's attribution is unclear; AI-assisted development is suggested but not confirmed.1
  • Unknown: The total number of victims actually compromised (as distinct from targeted); the identity of the kit's supplier, if one exists; and the full set of actors beyond the four Proofpoint names.1

Lessons and Defensive Recommendations

For SOC and endpoint teams:

  • Patch-gap zero-days mean "up to date on the stable channel" is not the same as "not vulnerable" during the window between an upstream commit and a stable rollout. Track high-severity V8/Chromium upstream commits, prioritise Chrome/Chromium updates the moment stable ships, and consider tighter update SLAs for high-risk users (executives, NGO staff, engineers) who are the targets here.
  • Hunt for the behavioural chain, not just the CVEs: a chrome.exe → cmd.exe → curl.exe process tree, scheduled tasks named to mimic updaters (EdgeCore_AutoUpdate, GeForceService), and unexpected Chrome extensions with broad permissions (cookies, tabs, scripting, webNavigation). The GemStone install forges Secure Preferences to avoid the Web Store, so an extension present without a corresponding Web Store install is a strong signal.

For browser and platform teams:

  • A malicious extension masquerading as an AI "Gemini" companion, installed by forging Secure Preferences HMAC, is a reminder that side-loaded/forced-installed extensions are a live post-exploitation vector. Enforce enterprise extension allowlisting, monitor for Secure Preferences tampering, and treat the browser's extension surface as part of the endpoint attack surface, not a convenience feature.

For leadership and threat intel:

  • The story here is capability diffusion: four espionage actors fielding the same chain within ~12 days suggests exploit kits are being shared or sold among state-aligned groups, compressing the time between a bug's disclosure and its use by multiple actors. Threat models that assume one exploit equals one actor understate this; assume that a patch-gap zero-day, once seen, is available to several.

Sources

Footnotes

  1. Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days — Proofpoint, September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37

  2. Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days — Security Affairs, September 2026 ↩ ↩2

  3. CVE-2026-85046 — National Vulnerability Database — NIST NVD, published September 3, 2026 (V8 type confusion in Chrome) ↩ ↩2 ↩3 ↩4 ↩5

  4. CVE-2026-85880 — National Vulnerability Database — NIST NVD, published September 8, 2026 (Windows ALPC heap overflow, local privilege escalation) ↩ ↩2 ↩3 ↩4 ↩5

Topics: #bluemoon#ta412#apt31#violet-typhoon#patch-gap-zero-day#v8-chrome#gemstone#proofpoint
Original Incident Report →

Related Research

GTIG tracked UNC6240 (linked to ShinyHunters) mass-exploiting PeopleSoft's CVE-2026-35273 (CVSS 9.8 unauth RCE). Defenders who blocked /PSEMHUB at a WAF instead of patching were bypassed: the actor requested /%50SEMHUB/, one URL-encoded character, then dropped web shells and the SIDEEYE backdoor.

Data BreachMalwareExtortion & Blackmail

Rapid7 found 'ted', a backdoor a DPRK-linked APT compiled into victims' HAProxy load balancers as a native plugin — reading their decrypted traffic and routing C2 through the load balancer itself. A companion CurlRAT toolkit hid in five trojanized Linux daemons; targets were South Korean firms.

State-SponsoredMalware

Mandiant documents an intrusion where an AI coding assistant recommended attacker-poisoned software; a developer accepted it, and the attacker used the live session to steal GitHub OAuth tokens and spread the Shai-Hulud worm across ~100 internal repos. How the session was taken over is undisclosed.

Supply Chain AttackAI & Machine LearningMalware