Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days

Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days
Proofpoint reported that multiple espionage-oriented threat actors rapidly adopted the BlueMoon exploit kit, which chains Chrome V8 and Windows vulnerabilities to deliver different payloads and backdoors. The activity affected US NGOs, US aerospace and defense-related organizations, Vietnamese manufacturing, and targets in Singapore and Indonesia, with notable payloads including GemStone and ShadowPad. #BlueMoon #TA412 #ShadowPad #GemStone #UNK_LateNight #UNK_DoubleCheck #UNK_QuietRacket

Keypoints

  • Proofpoint identified four espionage-motivated threat actors using the BlueMoon exploit kit in late August and September 2026.
  • BlueMoon chains a Chrome V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel LPE zero-day (CVE-2026-85880).
  • The first observed user was TA412, which targeted US NGOs, mining firms, and physical commodity trading organizations.
  • TA412’s post-exploitation activity installed the GemStone malicious Chrome extension to enable surveillance and credential theft.
  • UNK_LateNight used BlueMoon against US aerospace firms to deliver the ShadowPad backdoor through a DLL sideloading chain.
  • UNK_DoubleCheck targeted a Vietnamese manufacturing entity with a Rust loader infection chain and multiple external download domains.
  • UNK_QuietRacket targeted organizations in Indonesia and Singapore and used modified BlueMoon payloads, DNS-over-HTTPS, and scheduled-task persistence.

MITRE Techniques

  • [T1203] Exploitation for Client Execution – BlueMoon exploited browser vulnerabilities to run code in the renderer process (‘the exploit chain targets… a type-confusion vulnerability in Chromium’s V8 JavaScript engine… a V8 sandbox escape’).
  • [T1068] Exploitation for Privilege Escalation – The kit used a Windows kernel LPE zero-day to gain higher privileges (‘a Windows kernel Local Privilege Escalation (LPE) zero-day’).
  • [T1055] Process Injection – BlueMoon injected code into browser processes and other targets (‘injects a CreateProcess stub into the parent Chrome broker process’, ‘attempts to inject the decrypted contents into one of several hardcoded injection targets’).
  • [T1105] Ingress Tool Transfer – The payload stage downloaded executables and components from remote servers (‘downloads an actor-provided executable to disk and executes it’, ‘curl.exe -k -o …’).
  • [T1218.005] System Binary Proxy Execution: Mshta – Not mentioned.
  • [T1027] Obfuscated Files or Information – Multiple campaigns used encoding, obfuscation, or Base64/ChaCha20/RC4 protection (‘encoded or obfuscated its components’, ‘Base64-encoded components’, ‘ChaCha20-decrypting it’).
  • [T1112] Modify Registry – BlueMoon-related payloads wrote persistence data to the registry (‘the payload is written to registry as a backup storage mechanism’, ‘registry writes to HKCUSOFTWAREClassesCLSID…InprocServer32’).
  • [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – Not mentioned.
  • [T1053.005] Scheduled Task/Job: Scheduled Task – Campaigns created scheduled tasks for persistence (‘A scheduled task named EdgeCore_AutoUpdate is created’, ‘scheduled task GeForceService’).
  • [T1562.001] Impair Defenses: Disable or Modify Tools – The TA412 installer bypassed Chromium Secure Preferences protections (‘defeats this by using the same inputs the browser uses’).
  • [T1113] Screen Capture – GemStone could capture screenshots on command or via keyword triggers (‘SCREENSHOT_NOW’, ‘Upload screenshot’).
  • [T1056.001] Input Capture: Keylogging – GemStone recorded keystrokes and input events (‘listens in capture mode for keydown, input, change, and paste’).
  • [T1041] Exfiltration Over C2 Channel – GemStone exfiltrated collected data to its C&C endpoint (‘regularly exfiltrates data in JSON format’).
  • [T1071.001] Application Layer Protocol: Web Protocols – The malware used HTTP/HTTPS for registration, polling, exfiltration, and beacons (‘HTTP POST request’, ‘beacons over HTTPS’).
  • [T1071.004] Application Layer Protocol: DNS – UNK_QuietRacket resolved infrastructure via DNS TXT lookups (‘retrieving a TXT record for dns.elixnovorem[.]com’).
  • [T1036] Masquerading – TA412 disguised its extension as a Google Gemini product and other lures impersonated legitimate organizations (‘masquerades as an “AI-powered browsing companion by Google Gemini”’).

Indicators of Compromise

  • [SHA256 ] BlueMoon exploit JS and payloads – 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d, ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b, and 3 more hashes
  • [SHA256 ] Other campaign files – a4a6a04d85eca8d584d939d2437c85a4f291207d8042f2ec002838e336b72ef5, b34802a646fc4a8f07ffa09a5fda8bf7327446b22e3d7bb5163dafa1e2a8bb2b, and 10 more hashes
  • [Domain ] BlueMoon delivery and download domains – secboxes[.]com, msbenefit[.]com, and other 20 items
  • [Hostname ] Exploit pages, C&C, and download hosts – recommendation-letter.secboxes[.]com, extension-management-portal.centerfjdr658.workers[.]dev, and other 20 items
  • [URL ] Download URLs for ChromeUpdate, msgbox.exe, and loaders – hxxps://project.secboxes[.]com/ChromeUpdate.exe, hxxps://evidence.msbenefit[.]com/msgbox.exe, and other 15 items
  • [Email address ] Sender accounts used in phishing – zfg.rc.420@gmail[.]com, laylowthiago@gmail[.]com, and other 11 items
  • [IP address ] ShadowPad fallback C&C server – 79.133.56[.]90
  • [File name ] Malicious and supporting files – driver-html.js, msgbox.exe, background.js, and other 10 items


Read more: https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit