Exploit Kit Chains Browser and OS Flaws for Espionage Campaigns

A modular exploit kit called BlueMoon has been observed combining zero-day vulnerabilities in Chromium-based browsers and Windows to achieve remote code execution and privilege escalation. Proofpoint and Volexity attribute its use to Chinese-linked APT31 and another actor targeting NGOs, with operations starting in late August 2026. The kit exploits a delay between public Chromium fixes and stable Chrome releases, chaining three specific CVEs including a Windows ALPC heap overflow.
The exploit sequence executes within a Web Worker, attempting the chain up to five times, and combines a V8 type confusion, a V8 sandbox escape, and a Windows ALPC overflow. The privilege escalation tool's 2025 compilation timestamp indicates it was repurposed from an existing capability.
Beyond the initial APT31 and UTA0560 operations, two additional clusters were observed: one deploying ShadowPad against US aerospace and defense firms, and another using a Rust loader against Vietnamese manufacturers. The modular nature of the kit points to likely wider adoption.
The exploitation of widely used browser and operating system components could expose a broad range of organizations to sophisticated espionage, particularly NGOs and critical industrial sectors. Because the kit leverages the gap between open-source fixes and stable releases, ordinary users may face a window of vulnerability. Widespread adoption by financially motivated actors could eventually democratize these advanced techniques, potentially increasing cybercrime risks for the general public.