Back to feed

Four China-linked groups exploit Chrome and Windows zero-day chain since late August

2 min
Four China-linked groups exploit Chrome and Windows zero-day chain since late August

This digest was compiled by AI from multiple sources — links to the originals are below.

At least four China-aligned espionage groups have exploited a chain of three zero-day vulnerabilities in Chrome and Windows since late August, Proofpoint researchers said. The groups targeted NGOs, mining companies, and commodity trading firms in the United States. The activity is ongoing and expected to widen.

Key Facts

  • Proofpoint observed at least four state-aligned threat groups exploiting the BlueMoon chain since late August.
  • The chain targets Chrome, Chromium-based browsers, and Microsoft Windows, allowing code execution, sandbox escape, and privilege escalation.
  • The vulnerabilities are CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, all exploited before public patches were available.
  • APT31, also tracked as TA412 and Violet Typhoon, first exploited the chain on Aug. 28, targeting U.S. NGOs, mining companies, and commodity trading firms.
  • Proofpoint observed BlueMoon usage as recently as Sept. 8, 2026.

Exploit Chain Details

The BlueMoon exploit chain targets Chrome, Chromium-based browsers, and Microsoft Windows. It enables attackers to execute code in the browser sandbox, escape the sandbox, and gain system privileges on the targeted machine. The chain consists of CVE-2026-85046 and CVE-2026-87491, remote-code execution flaws in the JavaScript engine of Chromium-based browsers, and CVE-2026-85880, a privilege-escalation zero-day in Windows Advanced Local Procedure Call disclosed by Microsoft on Tuesday. Proofpoint staff threat researcher Mark Kelly said all three vulnerabilities were exploited before patches were publicly available. The V8 vulnerabilities were known and fixed in Chromium source code but not yet patched in publicly available browsers at the time of the activity, effectively functioning as zero-days.

Attribution and Targeting

APT31, also tracked as TA412 and Violet Typhoon, first exploited the chain on Aug. 28, 2026. APT31 has conducted espionage on behalf of China's Ministry of State Security, and seven Chinese nationals linked to the group were indicted by the U.S. Justice Department in 2024. The group used phishing emails with lures containing the exploit chain loader to target non-governmental organizations, mining companies, and commodity trading firms in the United States. The phishing link installed a malicious browser extension disguised as Google Gemini, enabling attackers to surveil browser activity, steal credentials, and execute commands. At least three additional espionage threat groups exploited the same vulnerabilities in subsequent waves of attacks days later, with slight technical changes and varying targets.

Ongoing Activity

Proofpoint said the activity is ongoing and expects it to widen. The exploit kit developer likely reverse engineered publicly available Chromium patches to weaponize the browser exploit chain during the gap before browser updates. In all observed cases, the infrastructure used for exploit delivery was created on the same day as, or in the days immediately preceding, the associated campaigns. Proofpoint observed BlueMoon usage as recently as Sept. 8, 2026.

1 source

Time · lag behind first