Proofpoint Says TA412 Violet Typhoon Chained Chrome And Windows Zero-Days In BlueMoon Espionage
Image: The Register

Technology and Science · 09 September, 2026 · 3 min read

Proofpoint Says TA412 Violet Typhoon Chained Chrome And Windows Zero-Days In BlueMoon Espionage

Happened

BlueMoon exploit kit chains three Chrome and Windows zero-days. TA412/Violet Typhoon and other Chinese-state groups used it since August.

Split on

Whether AI is proven or only indicated.

Left out

2 of 3 outlets skipped it: default payload behaviour is a curl download-and-execute.

10outlets compared

Ars TechnicaCyberScoopCyberSecurityNewsDiarioBitcoinNashwan NewsProofpointSC MediaThe Hacker News

Same story, two versions

tap a side to read it in full

ProofpointProofpoint

Although no single artifact conclusively confirms AI-assisted development of BlueMoon
Read the original

Ars TechnicaArs Technica

Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.
Read the original
VS

Ars Technica leans on AI as a likely contributor, while Proofpoint says no artifact conclusively confirms it.

BlueMoon exploit chain

Proofpoint researchers said they spotted at least four state-aligned threat groups chaining a trio of zero-day vulnerabilities to conduct espionage on targets of interest to China’s government since late August, with the first activity attributed to TA412, also known as Violet Typhoon and APT31, exploiting the chain on Aug. P28.

Proofpoint researchers have spotted at least four state-aligned threat groups

CyberScoopCyberScoop

Proofpoint’s Mark Kelly said the exploit chain “allows attackers to run code in the browser’s sandbox, escape the sandbox and gain system privileges,” and the vulnerabilities included CVE-2026-85046 and CVE-2026-87491 in the JavaScript engine for Chromium-based browsers and CVE-2026-85880, a privilege-escalation zero-day Microsoft disclosed Tuesday in Windows Advanced Local Procedure Call.P

Image from Ars Technica
Ars TechnicaArs Technica

CyberScoop reported that Proofpoint tracked the exploit kit as BlueMoon, which targeted Chrome, Chromium-based browsers and Microsoft Windows, and it said the exploit chain was used in subsequent waves by additional espionage threat groups days later.P

The Hacker News described BlueMoon as an exploit kit that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome, and it said the first in-the-wild use was attributed to APT31 on August 28, 2026.

Proofpoint also said the “infrastructure used for exploit delivery was created on the same day as — or in the days immediately preceding — the associated campaigns,” suggesting rapid deployment rather than long planning.P

Targets, lures, and attribution

Proofpoint said TA412 dropped phishing emails containing the exploit chain loader targeting non-governmental organizations, mining companies and commodity trading firms in the United States, and the phishing link installed a malicious browser extension disguised as Google Gemini on targeted machines.P

Nascent cluster names also appeared in Proofpoint reporting, including UNK_LateNight targeting multiple U.S. aerospace companies Sept. P2 and UNK_DoubleCheck targeting Vietnamese manufacturing organizations with emails from a compromised Southeast Asian government account.

Image from CyberScoop
CyberScoopCyberScoop

CyberScoop reported that Proofpoint observed BlueMoon usage as recently as Sept. P8, with activity peaking Sept. 2-3 immediately prior to the Chrome patch being released and continuing intermittently since then.

The Record from Recorded Future News quoted Mark Kelly saying, “There’s no way that this is parallel development,” adding that “The code is practically identical — even the variable naming, the commentary.”

Ars Technica said Proofpoint described BlueMoon as chaining three vulnerabilities together so attackers using it can install malware of their choice, and it listed Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11 among affected versions.

Patch gaps and next risks

Proofpoint said both V8 vulnerabilities were “patch-gap” zero-days at the time of the observed activity, meaning they were known and fixed in Chromium source code but not yet patched in the latest publicly available browsers when attackers exploited the chain.P

“All three vulnerabilities were exploited before patches were available to the public,” he said

CyberScoopCyberScoop

The Record from Recorded Future News described the exploit’s timing as a patch gap where changes to Chromium’s public code took four weeks before reaching stable Chrome users, and it said that created a window for attackers to study the public code and build an exploit before the fix reached users.

Ars Technica reported that BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days, and it said this may reflect a reduced cost and barrier to entry for a fully weaponized Chrome exploit chain.A

CyberScoop quoted Mark Kelly saying, “Given its ease of adoption, we expect the exploit kit is likely to proliferate further,” and it tied that expectation to patched versions being fully rolled out across all Chromium-based browsers.

The Register reported that Microsoft patched the Windows bug (CVE-2026-85880) on Tuesday and that a Google spokesperson declined to comment beyond what Proofpoint wrote, while Proofpoint said damage appeared limited and that it had seen fewer than 20 organizations globally targeted thus far.P