Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
ID: 9905b13f-2cb2-5156-a829-a38328ef6938
STIX ID: report--9905b13f-2cb2-5156-a829-a38328ef6938
Feed Name: The Register (Security)
Proofpoint researchers uncovered BlueMoon, a rapidly developed exploit kit chaining two Chromium V8 flaws (one tracked as CVE-2026-85046 and a sandbox escape) with a Windows ALPC privilege escalation (CVE-2026-85880). Multiple espionage-motivated groups—mostly with suspected China links, including TA412—used phishing lures to deliver loaders that installed a malicious browser extension (GemStone) and other payloads such as ShadowPad, enabling credential theft, browser surveillance, screenshots, and keylogging across targeted NGOs, aerospace, government, and private sector organizations in the US and Southeast Asia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
