BlueMoon exploit kit deployment across espionage clusters
Malware Activity
Summary
Hide ▲
Show ▼
The BlueMoon exploit kit is being actively deployed across multiple espionage clusters, expanding a rare chained-exploit capability that combines Google Chrome and Microsoft Windows flaws. The activity matters because the kit is used to trigger code execution, bypass browser defenses, and deliver follow-on payloads such as DLL sideloading and browser add-ons. The spread across several operators within days increases the chance of wider reuse before patched browser versions fully reach users.
Related Happenings
Malicious Chrome and Edge browser-extension campaign
Campaign
H score16
First: 30.08.2026 17:17
Last: 30.08.2026 17:17
Sources 1
About this happening:
A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Malicious Chrome and Edge browser-extension campaign
CampaignAbout this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Superior malicious extension installation campaign
Campaign
H score17
First: 28.08.2026 18:27
Last: 28.08.2026 18:27
Sources 1
About this happening:
The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
Superior malicious extension installation campaign
CampaignAbout this happening: The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware Activity
H score30
First: 04.08.2026 22:03
Last: 04.08.2026 22:03
Sources 1
About this happening:
XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware ActivityAbout this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
Silver Fox MODBEACON Rust RAT activity
Malware Activity
H score23
First: 10.07.2026 16:15
Last: 10.07.2026 16:15
Sources 1
About this happening:
The Silver Fox ecosystem has been tied to MODBEACON, a Rust-based remote access trojan that gives operators encrypted C2 and modular control over infected hosts. T...
Silver Fox MODBEACON Rust RAT activity
Malware ActivityAbout this happening: The Silver Fox ecosystem has been tied to MODBEACON, a Rust-based remote access trojan that gives operators encrypted C2 and modular control over infected hosts. T...
KongTuke ClickFix and Teams access-seeking campaign
Campaign
H score33
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...
KongTuke ClickFix and Teams access-seeking campaign
CampaignAbout this happening: The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...
Latest development: 03.09.2026 13:43
KongTuke/Woodgnat actors have abused the signed Node.js/node.exe runtime to run attacker JavaScript and deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels since February 2026. One intrusion against an unspecified Asian technology company between March 23 and July 25, 2026 used the official Node.js installer from nodejs[.]org and EtherHiding to establish long-term access, and related attack chains also involve CrashFix, ModeloRAT, Mistic, GateKeeper, C2Looper, and AsukaStealer.
Timeline
-
09.09.2026 19:34 1 articles · 4h ago
APT31 delivers BlueMoon through spear-phishing to U.S. targets
Exploitation ObservedAPT31, also tracked as Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon, used spear-phishing lures starting on August 28, 2026 to target NGOs, mining companies, and physical commodity trading firms in the U.S. A malicious link served BlueMoon, which then loaded a browser add-on disguised as Google Gemini and established the GemStone browser-surveillance and credential-theft backdoor.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
-
09.09.2026 19:34 1 articles · 4h ago
BlueMoon reaches U.S. aerospace companies and a Vietnamese manufacturer
Campaign Scope UpdateBeginning on September 2, 2026, UNK_LateNight used spear-phishing lures against multiple U.S. aerospace companies, while UNK_DoubleCheck targeted a Vietnamese manufacturing entity and sent victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon. The chain used BlueMoon to trigger DLL sideloading, drop a Rust binary, and fetch a second sideloading pair from a Cloudflare R2 Bucket.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
-
09.09.2026 19:34 1 articles · 4h ago
BlueMoon lands on government, consulting, and financial targets in Indonesia and Singapore
Campaign Scope UpdateBeginning on September 3, 2026, UNK_QuietRacket used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore. The landing pages deployed BlueMoon, which downloaded and executed a DLL sideloading pair, used Cloudflare Workers domains to fetch a .NET assembly in memory, and created a scheduled task to preserve persistence.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
-
09.09.2026 19:34 1 articles · 4h ago
CISA adds CVE-2026-85046 to the Known Exploited Vulnerabilities catalog
Legal Policy Action UpdateOn 4 September, CISA added the Chrome flaw CVE-2026-85046 to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies until 18 September to patch. The deadline followed Google's fix and underscored that downstream Chromium-based browsers can remain exposed until updates fully propagate.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
-
09.09.2026 19:34 2 articles · 4h ago
Proofpoint publishes BlueMoon analysis
Initial DisclosureProofpoint published analysis of BlueMoon as a previously undocumented exploit kit that chained CVE-2026-85046 in Google Chrome with CVE-2026-85880 in Windows ALPC. The report said the campaigns began with phishing emails, used BlueMoon to trigger code execution and browser sandbox escape, and then leveraged a Windows local privilege escalation path, reflectively loaded DLLs, and a curl-based downloader to deliver follow-on payloads.
Show sources
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week — thehackernews.com — 09.09.2026 19:34