BlueMoon kit: APT31/JungleBamboo + UTA0560 GRIMWEDGE chain Chrome/Windows 0-days
Proofpoint (9 September 2026) documents BlueMoon, chaining CVE-2026-85046 (Chrome V8 type confusion), CVE-2026-87491 (V8/WebAssembly sandbox escape; patch-gap 0-day), and CVE-2026-85880 (Windows ALPC heap overflow LPE / AppContainer escape; Microsoft September Patch Tuesday + CISA KEV). First in-the-wild use attributed to China-aligned APT31 (Violet Typhoon / Judgement Panda / JungleBamboo) from 28 August 2026; other espionage clusters rapidly reused the kit. UPDATE 15 September 2026 desk (Volexity blog 9 Sep; THN wire 15 Sep): Volexity details two China-nexus clusters using the same byte-identical exploit chain against NGOs via spearphishing through reflected XSS on a legitimate US university site. UTA0560 deploys GRIMWEDGE (obfuscated JavaScript backdoor via MSI custom actions; C2 ocr.opusaccel[.]top; recon/file/process/Run/Upload; no built-in persistence). JungleBamboo/APT31 deploys SUPERSTOMP loader then LONGTALE (aka GemStone) credential-stealing Chrome extension masquerading as Google Gemini (keylogging, cookies, screenshots, ~30s exfil). Distinct from desk cards cve-2026-85046 / cve-2026-87491 / ms-september-2026-patch-tuesday — this card is the shared kit and post-exploitation. Primary: Proofpoint; secondary: Volexity; wire: THN.
- Product
- Google Chrome / Chromium; Microsoft Windows (ALPC)
- Versions
- Chrome lacking CVE-2026-85046 / CVE-2026-87491 stable builds (patch-gap 0-days); Windows prior to September 2026 CVE-2026-85880 updates
- Exploited in Australia?
- unknown
- Patch to
- Update Chrome/Edge/Chromium to builds with CVE-2026-85046 and CVE-2026-87491; apply Microsoft September 2026 updates for CVE-2026-85880; hunt NGO spearphishing / XSS redirects and GRIMWEDGE/LONGTALE indicators per Volexity
Primary: Proofpoint — BlueMoon exploit kit (9 Sep 2026) · Vendor: Microsoft — CVE-2026-85880 · CVE: CVE-2026-85046, CVE-2026-87491, CVE-2026-85880 · Volexity — UTA0560 GRIMWEDGE / JungleBamboo LONGTALE (9 Sep 2026); THN 15 Sep
