Proofpoint reported that multiple espionage-oriented threat actors rapidly adopted the BlueMoon exploit kit, which chains Chrome V8 and Windows vulnerabilities to deliver different payloads and backdoors. The activity affected US NGOs, US aerospace and defense-related organizations, Vietnamese manufacturing, and targets in Singapore and Indonesia, with notable payloads including GemStone and ShadowPad. #BlueMoon #TA412 #ShadowPad #GemStone #UNK_LateNight #UNK_DoubleCheck #UNK_QuietRacket
Keypoints
- Proofpoint identified four espionage-motivated threat actors using the BlueMoon exploit kit in late August and September 2026.
- BlueMoon chains a Chrome V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel LPE zero-day (CVE-2026-85880).
- The first observed user was TA412, which targeted US NGOs, mining firms, and physical commodity trading organizations.
- TA412âs post-exploitation activity installed the GemStone malicious Chrome extension to enable surveillance and credential theft.
- UNK_LateNight used BlueMoon against US aerospace firms to deliver the ShadowPad backdoor through a DLL sideloading chain.
- UNK_DoubleCheck targeted a Vietnamese manufacturing entity with a Rust loader infection chain and multiple external download domains.
- UNK_QuietRacket targeted organizations in Indonesia and Singapore and used modified BlueMoon payloads, DNS-over-HTTPS, and scheduled-task persistence.
MITRE Techniques
- [T1203] Exploitation for Client Execution â BlueMoon exploited browser vulnerabilities to run code in the renderer process (âthe exploit chain targets⌠a type-confusion vulnerability in Chromiumâs V8 JavaScript engine⌠a V8 sandbox escapeâ).
- [T1068] Exploitation for Privilege Escalation â The kit used a Windows kernel LPE zero-day to gain higher privileges (âa Windows kernel Local Privilege Escalation (LPE) zero-dayâ).
- [T1055] Process Injection â BlueMoon injected code into browser processes and other targets (âinjects a CreateProcess stub into the parent Chrome broker processâ, âattempts to inject the decrypted contents into one of several hardcoded injection targetsâ).
- [T1105] Ingress Tool Transfer â The payload stage downloaded executables and components from remote servers (âdownloads an actor-provided executable to disk and executes itâ, âcurl.exe -k -o âŚâ).
- [T1218.005] System Binary Proxy Execution: Mshta â Not mentioned.
- [T1027] Obfuscated Files or Information â Multiple campaigns used encoding, obfuscation, or Base64/ChaCha20/RC4 protection (âencoded or obfuscated its componentsâ, âBase64-encoded componentsâ, âChaCha20-decrypting itâ).
- [T1112] Modify Registry â BlueMoon-related payloads wrote persistence data to the registry (âthe payload is written to registry as a backup storage mechanismâ, âregistry writes to HKCUSOFTWAREClassesCLSIDâŚInprocServer32â).
- [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder â Not mentioned.
- [T1053.005] Scheduled Task/Job: Scheduled Task â Campaigns created scheduled tasks for persistence (âA scheduled task named EdgeCore_AutoUpdate is createdâ, âscheduled task GeForceServiceâ).
- [T1562.001] Impair Defenses: Disable or Modify Tools â The TA412 installer bypassed Chromium Secure Preferences protections (âdefeats this by using the same inputs the browser usesâ).
- [T1113] Screen Capture â GemStone could capture screenshots on command or via keyword triggers (âSCREENSHOT_NOWâ, âUpload screenshotâ).
- [T1056.001] Input Capture: Keylogging â GemStone recorded keystrokes and input events (âlistens in capture mode for keydown, input, change, and pasteâ).
- [T1041] Exfiltration Over C2 Channel â GemStone exfiltrated collected data to its C&C endpoint (âregularly exfiltrates data in JSON formatâ).
- [T1071.001] Application Layer Protocol: Web Protocols â The malware used HTTP/HTTPS for registration, polling, exfiltration, and beacons (âHTTP POST requestâ, âbeacons over HTTPSâ).
- [T1071.004] Application Layer Protocol: DNS â UNK_QuietRacket resolved infrastructure via DNS TXT lookups (âretrieving a TXT record for dns.elixnovorem[.]comâ).
- [T1036] Masquerading â TA412 disguised its extension as a Google Gemini product and other lures impersonated legitimate organizations (âmasquerades as an âAI-powered browsing companion by Google Geminiââ).
Indicators of Compromise
- [SHA256 ] BlueMoon exploit JS and payloads â 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096d, ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782b, and 3 more hashes
- [SHA256 ] Other campaign files â a4a6a04d85eca8d584d939d2437c85a4f291207d8042f2ec002838e336b72ef5, b34802a646fc4a8f07ffa09a5fda8bf7327446b22e3d7bb5163dafa1e2a8bb2b, and 10 more hashes
- [Domain ] BlueMoon delivery and download domains â secboxes[.]com, msbenefit[.]com, and other 20 items
- [Hostname ] Exploit pages, C&C, and download hosts â recommendation-letter.secboxes[.]com, extension-management-portal.centerfjdr658.workers[.]dev, and other 20 items
- [URL ] Download URLs for ChromeUpdate, msgbox.exe, and loaders â hxxps://project.secboxes[.]com/ChromeUpdate.exe, hxxps://evidence.msbenefit[.]com/msgbox.exe, and other 15 items
- [Email address ] Sender accounts used in phishing â zfg.rc.420@gmail[.]com, laylowthiago@gmail[.]com, and other 11 items
- [IP address ] ShadowPad fallback C&C server â 79.133.56[.]90
- [File name ] Malicious and supporting files â driver-html.js, msgbox.exe, background.js, and other 10 items