Chinese espionage groups swarm to exploit triple-link chain of zero-days

Chinese espionage groups swarm to exploit triple-link chain of zero-days
Proofpoint found at least four China-aligned threat groups chaining three zero-day flaws in Chrome, Chromium-based browsers, and Windows to carry out espionage since late August. The BlueMoon exploit chain has been used against NGOs, mining and commodity firms, U.S. aerospace companies, and organizations in Vietnam, Indonesia, and Singapore. #TA412 #VioletTyphoon #APT31 #BlueMoon #CVE-2026-85046 #CVE-2026-87491 #CVE-2026-85880 #UNK_LateNight #UNK_DoubleCheck #UNK_QuietRacket

Keypoints

  • Proofpoint tracked at least four state-aligned groups using a three-vulnerability exploit chain.
  • The BlueMoon chain targets Chrome, Chromium-based browsers, and Microsoft Windows.
  • The flaws were exploited before public patches were available.
  • APT31 used phishing emails to target NGOs, mining companies, and commodity firms in the U.S.
  • Other groups targeted aerospace, manufacturing, government, consulting, and financial organizations across Asia.

Read More: https://cyberscoop.com/china-espionage-groups-exploit-chain-zero-days/