DEV Community

Anoymask
Anoymask

Posted on

BlueMoon: A Shared Exploit Kit Chaining Chrome RCE, Sandbox Escape, and Windows Privilege Escalation

1. Basic Information

This article extends the earlier coverage of Windows CVE-2026-81963 and CVE-2026-85880. The BlueMoon chain described below involves CVE-2026-85880 alongside two Chromium vulnerabilities; this update does not establish that CVE-2026-81963 was part of that chain.

2. Executive Summary

Multiple espionage-focused threat clusters used BlueMoon in spearphishing campaigns, chaining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to inject code into Chrome's parent process and use curl to retrieve and execute malware.

3. Attack Flow

BlueMoon: From Chrome Exploitation to Windows Privilege Escalation

  1. A targeted email or associated landing page directs the victim to exploit code in a vulnerable Chrome or Chromium-based browser.
  2. CVE-2026-85046 provides memory access within the V8 sandbox.
  3. CVE-2026-87491 enables escape from the V8 sandbox. A reflectively loaded DLL then identifies the Windows version.
  4. On older Windows builds targeted by the exploit, CVE-2026-85880 elevates the renderer process's privileges.
  5. The kit injects a process-creation stub into Chrome's parent broker process, then uses curl to download a payload into %TEMP% and execute it.
  6. Follow-on payloads vary by actor and include Grimwedge, ShadowPad, and Rust-based loaders.

4. Attacker Position and Execution Environment

  • A remote attacker controls spearphishing infrastructure and can deliver a browser exploit kit to the victim.

5. What Users and Administrators May See

Users

  • Inference: After a victim follows a targeted email link or visits the associated web page, the payload may execute with little visible indication in the browser.

Administrators

  • Inference: Unusual code injection from Chrome's renderer into its broker process, browser-originated curl activity, executable files in %TEMP%, and connections to known landing pages or payload hosts can provide investigation leads. Visibility into in-memory loading and injection depends on the endpoint telemetry available.

6. Success Conditions and Risk Reduction

Success Conditions

  • The endpoint combines a vulnerable stable Chrome or Chromium-based browser with an older Windows build targeted by the privilege-escalation stage.
  • The victim opens the actor-controlled landing page in the browser.
  • Endpoint controls do not stop curl or payload execution from a browser child process or an injected process.

Failure Conditions and Risk Reduction

  • Update both Chrome or other Chromium-based browsers and Windows to patched versions, and verify that the browser has restarted.
  • Control and detect browser-related execution of curl, programs stored in %TEMP%, and unfamiliar executables.
  • Use email and web isolation, together with application control, to reduce exposure and block follow-on payloads.

7. Potential Impact

  • Code execution on Windows through a browser exploitation chain.
  • Reconnaissance, command execution, and payload deployment in the targeted environment.
  • Ongoing espionage through follow-on backdoors.

8. Observable Logs

Inference: The following are potential investigation sources based on the reported behavior. Availability depends on collection settings, product capabilities, and retention periods; these are not claims that every listed artifact was logged for every victim.

Email

  • Targeted messages, lures such as donation requests, and links to recently created landing pages.

Proxy / SWG / DNS

  • Campaign domains, requests for exploit scripts, and connections to payload URLs used by curl.
  • DNS records identify queried domains, not complete URL paths. Requests for scripts or payloads require appropriate proxy, secure web gateway, or endpoint visibility.

Endpoint / EDR

  • A reflectively loaded DLL in a Chrome renderer, injection into the broker process, browser-originated curl execution, and executable files under %TEMP%.
  • In-memory DLL loading and process injection require suitable EDR telemetry or memory analysis; ordinary file or process-creation logs alone may not expose them.

Identity / IdP

  • Direct authentication compromise is not part of the publicly described chain. Identity logs are relevant to investigating possible follow-on activity, not to proving the browser exploit itself succeeded.

SaaS / Cloud

  • Email delivery and web-isolation records, where these services are deployed.

Network

  • Connections to a landing page, exploit host, and payload command-and-control infrastructure within a short period.

9. Assessing Attack Success

The following summarizes the observations described in the updated reporting. It does not establish the same outcome for every recipient or for an organization investigating a matching indicator.

  • User interaction: The observed campaigns delivered browser exploits through targeted lures. The details of individual victims' interactions were not uniform.
  • Initial execution: The updated reporting describes Proofpoint and Volexity observing the three-vulnerability chain and payload retrieval and execution through curl in real-world activity.
  • Follow-on compromise: Follow-on payloads, including Grimwedge, ShadowPad, and Rust-based loaders, were observed across multiple clusters.

10. Investigation Playbook

Inference: These are operational recommendations derived from the reported behavior, not additional observations from the campaigns.

Trigger

  • Start an investigation when vulnerability exploitation, relevant indicators of compromise, suspicious authentication associated with the affected endpoint or account, or behavior described in this report is detected.

Initial Checks

  • Identify the asset, software versions, configuration, and exposure, together with the event time, source, and affected host or account identifiers.
  • Keep the scope of the researchers' observations separate from evidence confirmed in your own environment.

Endpoint

  • Build a timeline of relevant parent-child process relationships, file creation, privilege changes, persistence, and credential access.

Identity / Cloud

  • Check for authentication-method changes, token use, and cloud-data access associated with the same user, source, or session. These are follow-on checks, not evidence that identity compromise was part of the initial exploit chain.

Follow-on Investigation

  • Extend the investigation from the suspected initial compromise to internal discovery, lateral movement, command-and-control traffic, archive creation, and data transfers.

Containment

  • Isolate affected systems or restrict their exposure, and apply the relevant fixes. When compromise is confirmed or suspected, revoke affected sessions and rotate relevant keys, passwords, and other secrets according to the suspected impact.

Classification

  • Treat requests or contact with an indicator alone as evidence of an attempt. Record a later success stage only when supported by evidence of execution, successful authentication, or data access, as applicable.

11. Defense and Detection Ideas

Inference: Apply the following ideas to the telemetry and controls available in your environment.

Single Events

  • Targeted emails, donation-themed or similar lures, and links to recently created landing pages.
  • Campaign domains, exploit-script requests, and payload connections associated with curl.
  • Reflective DLL loading inside a Chrome renderer, injection into the broker process, browser-originated curl, and execution of files under %TEMP%.

Direct authentication compromise is not part of the publicly described chain. An authentication anomaly should be assessed as a separate or follow-on lead rather than assumed to be a required exploit stage.

Time-Series Correlation

  • Correlate suspicious authentication, configuration changes, discovery, large-scale access, and outbound traffic occurring within a short period and associated with the same entity. Keep browser and endpoint execution evidence central when assessing this chain.

Threat Hunting

  • Look beyond individual indicators and retrospectively search for processes, authentication activity, communications, and configuration changes that represent the same attack sequence.

Logging Gaps

  • Verify that the relevant logs are enabled, clocks are synchronized, retention is sufficient, and correlation keys are available across endpoints, cloud services, and perimeter devices.

Priority Controls

  • Patch both Chrome or other Chromium-based browsers and Windows, and confirm that browser restarts have occurred.
  • Control and detect browser-related curl execution, execution from %TEMP%, and unfamiliar executable files.
  • Use email and web isolation and application control to reduce exposure and block follow-on payloads.

12. Facts / Inference / Hypothesis

Facts

  • Microsoft fixed CVE-2026-81963 and CVE-2026-85880 in its September 2026 updates and identified both as exploited in the wild.
  • Proofpoint reported that four espionage-focused clusters had used BlueMoon in spearphishing campaigns since August 28, 2026.
  • The reported BlueMoon chain uses the V8 type-confusion flaw CVE-2026-85046 to obtain memory access inside the sandbox, CVE-2026-87491 to escape the V8 sandbox, and the Windows Advanced Local Procedure Call (ALPC) heap overflow CVE-2026-85880 to elevate privileges on older Windows builds.
  • The two Chromium flaws were exploited as patch-gap zero-days: fixes existed in the upstream project but had not yet reached stable browser releases.
  • The kit can retry exploitation up to five times inside a Web Worker. It fingerprints the host through a reflectively loaded DLL, elevates the renderer through local privilege escalation, and injects a CreateProcess stub into Chrome's parent broker process.
  • The default command uses curl to save a remote executable into %TEMP% and run it. Reported actors include JungleBamboo, UTA0560, UNK_LateNight, and UNK_DoubleCheck, with targeting spanning NGOs, mining, high-value individuals, aerospace and defense, and manufacturing.
  • Proofpoint identified debugging logs, references to a Markdown handover file in code comments, and detailed comments consistent with AI-assisted development, but cautioned that no single artifact establishes that AI was used to develop the kit.

Inference

  • The investigation and detection recommendations are derived from the publicly described attack behavior. The evidence available in a particular environment depends on logging configuration and retention.

Hypothesis

No additional hypotheses. Unresolved points are listed under Unknowns and Further Investigation.

13. MITRE ATT&CK Mapping

  • T1203 Exploitation for Client Execution (high confidence): Browser vulnerabilities are chained to execute code on the client.
  • T1068 Exploitation for Privilege Escalation (high confidence): CVE-2026-85880 is used to elevate privileges on Windows.
  • T1055 Process Injection (high confidence): A stub is injected into Chrome's parent broker process.
  • T1105 Ingress Tool Transfer (high confidence): curl retrieves a remote payload into %TEMP%.

14. Unknowns and Further Investigation

  • How multiple actors obtained the same exploit kit.
  • The extent to which generative AI was used in BlueMoon's development.
  • Whether CVE-2026-85880 was exploited before the observed 2026 campaigns. The DLL's 2025 compilation timestamp alone does not establish earlier exploitation.

15. Impact on SOCs and Organizations

Managing exposure across this chain requires tracking both browser and Windows patching, rather than treating updates for either product as the entire task. Organizations should account for the gap between Chromium's upstream fixes and their arrival in stable releases. During an urgent response, establish which browser versions are actually running, whether restarts have completed, and which endpoints still use older Windows builds.

SOCs should correlate the transition from Chrome to curl, execution from %TEMP%, process injection, and follow-on command-and-control traffic. Looking only for browser crashes or web indicators can miss the more consequential evidence of payload execution.

16. Audience Summaries

  • SOC: Correlate Chrome renderer and broker anomalies, browser-originated curl, execution from %TEMP%, campaign domains, and follow-on command-and-control traffic.
  • Administrators: Update both Chrome or other Chromium-based browsers and Windows. Verify restarts and the versions or builds actually in use, and isolate endpoints that remain on older vulnerable Windows builds.
  • Users: Avoid links in suspicious targeted emails, and complete the required restarts after browser and Windows updates.

Top comments (0)