Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
AI Summary
Multiple espionage-motivated threat actors, including APT31 and several China-aligned clusters, have leveraged a previously undocumented exploit kit named BlueMoon to exploit unpatched vulnerabilities in Google Chrome and Microsoft Windows. The exploit chain combines CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to achieve sandbox escape and local privilege escalation, delivered via phishing emails leading to malicious URLs. The kit downloads payloads such as the GemStone browser backdoor, ShadowPad, and Rust-based malware using DLL sideloading and in-memory execution techniques. The U.S. CISA has added all three CVEs to its KEV catalog, mandating federal agencies to patch them by mid-September 2026.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 11 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | ChromeUpdate.exe | Details → |
| Filename | msgbox.exe | Details → |
| Filename | curl.exe | Details → |
| Filename | cmd.exe | Details → |
| Filename | GeForceService | Details → |
| Filename | EdgeCore_AutoUpdate | Details → |
| Filename | MicrosoftEdgeUpdatesTaskMachine | Details → |
| Filename | Avpcheckup | Details → |
| Filename | Dataupcheckinfo | Details → |
| Filename | C:\Users\Public\stomp_ext | Details → |
| Registry User | HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32 | Details → |