Find notable cyber news and cases, enriched with sources, timelines, and signals.

BlueMoon exploit kit deployment across espionage clusters

Malware Activity
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

The BlueMoon exploit kit is being actively deployed across multiple espionage clusters, expanding a rare chained-exploit capability that combines Google Chrome and Microsoft Windows flaws. The activity matters because the kit is used to trigger code execution, bypass browser defenses, and deliver follow-on payloads such as DLL sideloading and browser add-ons. The spread across several operators within days increases the chance of wider reuse before patched browser versions fully reach users.

Related Happenings

Malicious Chrome and Edge browser-extension campaign

Campaign
H score16 First: 30.08.2026 17:17 Last: 30.08.2026 17:17 Sources 1

About this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...

Superior malicious extension installation campaign

Campaign
H score17 First: 28.08.2026 18:27 Last: 28.08.2026 18:27 Sources 1

About this happening: The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...

XCSSET v40 macOS malware activity via compromised Xcode projects

Malware Activity
H score30 First: 04.08.2026 22:03 Last: 04.08.2026 22:03 Sources 1

About this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...

Silver Fox MODBEACON Rust RAT activity

Malware Activity
H score23 First: 10.07.2026 16:15 Last: 10.07.2026 16:15 Sources 1

About this happening: The Silver Fox ecosystem has been tied to MODBEACON, a Rust-based remote access trojan that gives operators encrypted C2 and modular control over infected hosts. T...

KongTuke ClickFix and Teams access-seeking campaign

Campaign
H score33 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...

Latest development: 03.09.2026 13:43

KongTuke/Woodgnat actors have abused the signed Node.js/node.exe runtime to run attacker JavaScript and deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels since February 2026. One intrusion against an unspecified Asian technology company between March 23 and July 25, 2026 used the official Node.js installer from nodejs[.]org and EtherHiding to establish long-term access, and related attack chains also involve CrashFix, ModeloRAT, Mistic, GateKeeper, C2Looper, and AsukaStealer.

Timeline

  1. 09.09.2026 19:34 1 articles · 4h ago

    APT31 delivers BlueMoon through spear-phishing to U.S. targets

    Exploitation Observed

    APT31, also tracked as Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon, used spear-phishing lures starting on August 28, 2026 to target NGOs, mining companies, and physical commodity trading firms in the U.S. A malicious link served BlueMoon, which then loaded a browser add-on disguised as Google Gemini and established the GemStone browser-surveillance and credential-theft backdoor.

    Show sources
  2. 09.09.2026 19:34 1 articles · 4h ago

    BlueMoon reaches U.S. aerospace companies and a Vietnamese manufacturer

    Campaign Scope Update

    Beginning on September 2, 2026, UNK_LateNight used spear-phishing lures against multiple U.S. aerospace companies, while UNK_DoubleCheck targeted a Vietnamese manufacturing entity and sent victims to an actor-controlled Cloudflare Workers domain hosting BlueMoon. The chain used BlueMoon to trigger DLL sideloading, drop a Rust binary, and fetch a second sideloading pair from a Cloudflare R2 Bucket.

    Show sources
  3. 09.09.2026 19:34 1 articles · 4h ago

    BlueMoon lands on government, consulting, and financial targets in Indonesia and Singapore

    Campaign Scope Update

    Beginning on September 3, 2026, UNK_QuietRacket used spear-phishing lures to target government, consulting, and financial sector organizations in Indonesia and Singapore. The landing pages deployed BlueMoon, which downloaded and executed a DLL sideloading pair, used Cloudflare Workers domains to fetch a .NET assembly in memory, and created a scheduled task to preserve persistence.

    Show sources
  4. 09.09.2026 19:34 1 articles · 4h ago

    CISA adds CVE-2026-85046 to the Known Exploited Vulnerabilities catalog

    Legal Policy Action Update

    On 4 September, CISA added the Chrome flaw CVE-2026-85046 to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies until 18 September to patch. The deadline followed Google's fix and underscored that downstream Chromium-based browsers can remain exposed until updates fully propagate.

    Show sources
  5. 09.09.2026 19:34 2 articles · 4h ago

    Proofpoint publishes BlueMoon analysis

    Initial Disclosure

    Proofpoint published analysis of BlueMoon as a previously undocumented exploit kit that chained CVE-2026-85046 in Google Chrome with CVE-2026-85880 in Windows ALPC. The report said the campaigns began with phishing emails, used BlueMoon to trigger code execution and browser sandbox escape, and then leveraged a Windows local privilege escalation path, reflectively loaded DLLs, and a curl-based downloader to deliver follow-on payloads.

    Show sources