1. Basic Information
- Original Coverage: BleepingComputer's September 2026 Patch Tuesday report
- Update Coverage: New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
- Publisher: BleepingComputer
- Original Publication Date: 2026-09-08
- Update Date: 2026-09-10
- Priority: Critical
- Priority Rationale: Multiple threat actors have exploited a browser-to-kernel chain in the wild. By taking advantage of the gap between upstream fixes and stable browser releases, they can progress from a user's browser interaction to code execution on Windows.
- Related Research: Proofpoint's BlueMoon analysis, Volexity's BlueMoon analysis
- Reason for Update: Proofpoint and Volexity published details of the BlueMoon exploit chain involving CVE-2026-85880, including the actors, targets, execution sequence, and follow-on payloads.
This article extends the earlier coverage of Windows CVE-2026-81963 and CVE-2026-85880. The BlueMoon chain described below involves CVE-2026-85880 alongside two Chromium vulnerabilities; this update does not establish that CVE-2026-81963 was part of that chain.
2. Executive Summary
Multiple espionage-focused threat clusters used BlueMoon in spearphishing campaigns, chaining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to inject code into Chrome's parent process and use curl to retrieve and execute malware.
3. Attack Flow
BlueMoon: From Chrome Exploitation to Windows Privilege Escalation
- A targeted email or associated landing page directs the victim to exploit code in a vulnerable Chrome or Chromium-based browser.
- CVE-2026-85046 provides memory access within the V8 sandbox.
- CVE-2026-87491 enables escape from the V8 sandbox. A reflectively loaded DLL then identifies the Windows version.
- On older Windows builds targeted by the exploit, CVE-2026-85880 elevates the renderer process's privileges.
- The kit injects a process-creation stub into Chrome's parent broker process, then uses
curlto download a payload into%TEMP%and execute it. - Follow-on payloads vary by actor and include Grimwedge, ShadowPad, and Rust-based loaders.
4. Attacker Position and Execution Environment
- A remote attacker controls spearphishing infrastructure and can deliver a browser exploit kit to the victim.
5. What Users and Administrators May See
Users
- Inference: After a victim follows a targeted email link or visits the associated web page, the payload may execute with little visible indication in the browser.
Administrators
- Inference: Unusual code injection from Chrome's renderer into its broker process, browser-originated
curlactivity, executable files in%TEMP%, and connections to known landing pages or payload hosts can provide investigation leads. Visibility into in-memory loading and injection depends on the endpoint telemetry available.
6. Success Conditions and Risk Reduction
Success Conditions
- The endpoint combines a vulnerable stable Chrome or Chromium-based browser with an older Windows build targeted by the privilege-escalation stage.
- The victim opens the actor-controlled landing page in the browser.
- Endpoint controls do not stop
curlor payload execution from a browser child process or an injected process.
Failure Conditions and Risk Reduction
- Update both Chrome or other Chromium-based browsers and Windows to patched versions, and verify that the browser has restarted.
- Control and detect browser-related execution of
curl, programs stored in%TEMP%, and unfamiliar executables. - Use email and web isolation, together with application control, to reduce exposure and block follow-on payloads.
7. Potential Impact
- Code execution on Windows through a browser exploitation chain.
- Reconnaissance, command execution, and payload deployment in the targeted environment.
- Ongoing espionage through follow-on backdoors.
8. Observable Logs
Inference: The following are potential investigation sources based on the reported behavior. Availability depends on collection settings, product capabilities, and retention periods; these are not claims that every listed artifact was logged for every victim.
- Targeted messages, lures such as donation requests, and links to recently created landing pages.
Proxy / SWG / DNS
- Campaign domains, requests for exploit scripts, and connections to payload URLs used by
curl. - DNS records identify queried domains, not complete URL paths. Requests for scripts or payloads require appropriate proxy, secure web gateway, or endpoint visibility.
Endpoint / EDR
- A reflectively loaded DLL in a Chrome renderer, injection into the broker process, browser-originated
curlexecution, and executable files under%TEMP%. - In-memory DLL loading and process injection require suitable EDR telemetry or memory analysis; ordinary file or process-creation logs alone may not expose them.
Identity / IdP
- Direct authentication compromise is not part of the publicly described chain. Identity logs are relevant to investigating possible follow-on activity, not to proving the browser exploit itself succeeded.
SaaS / Cloud
- Email delivery and web-isolation records, where these services are deployed.
Network
- Connections to a landing page, exploit host, and payload command-and-control infrastructure within a short period.
9. Assessing Attack Success
The following summarizes the observations described in the updated reporting. It does not establish the same outcome for every recipient or for an organization investigating a matching indicator.
- User interaction: The observed campaigns delivered browser exploits through targeted lures. The details of individual victims' interactions were not uniform.
-
Initial execution: The updated reporting describes Proofpoint and Volexity observing the three-vulnerability chain and payload retrieval and execution through
curlin real-world activity. - Follow-on compromise: Follow-on payloads, including Grimwedge, ShadowPad, and Rust-based loaders, were observed across multiple clusters.
10. Investigation Playbook
Inference: These are operational recommendations derived from the reported behavior, not additional observations from the campaigns.
Trigger
- Start an investigation when vulnerability exploitation, relevant indicators of compromise, suspicious authentication associated with the affected endpoint or account, or behavior described in this report is detected.
Initial Checks
- Identify the asset, software versions, configuration, and exposure, together with the event time, source, and affected host or account identifiers.
- Keep the scope of the researchers' observations separate from evidence confirmed in your own environment.
Endpoint
- Build a timeline of relevant parent-child process relationships, file creation, privilege changes, persistence, and credential access.
Identity / Cloud
- Check for authentication-method changes, token use, and cloud-data access associated with the same user, source, or session. These are follow-on checks, not evidence that identity compromise was part of the initial exploit chain.
Follow-on Investigation
- Extend the investigation from the suspected initial compromise to internal discovery, lateral movement, command-and-control traffic, archive creation, and data transfers.
Containment
- Isolate affected systems or restrict their exposure, and apply the relevant fixes. When compromise is confirmed or suspected, revoke affected sessions and rotate relevant keys, passwords, and other secrets according to the suspected impact.
Classification
- Treat requests or contact with an indicator alone as evidence of an attempt. Record a later success stage only when supported by evidence of execution, successful authentication, or data access, as applicable.
11. Defense and Detection Ideas
Inference: Apply the following ideas to the telemetry and controls available in your environment.
Single Events
- Targeted emails, donation-themed or similar lures, and links to recently created landing pages.
- Campaign domains, exploit-script requests, and payload connections associated with
curl. - Reflective DLL loading inside a Chrome renderer, injection into the broker process, browser-originated
curl, and execution of files under%TEMP%.
Direct authentication compromise is not part of the publicly described chain. An authentication anomaly should be assessed as a separate or follow-on lead rather than assumed to be a required exploit stage.
Time-Series Correlation
- Correlate suspicious authentication, configuration changes, discovery, large-scale access, and outbound traffic occurring within a short period and associated with the same entity. Keep browser and endpoint execution evidence central when assessing this chain.
Threat Hunting
- Look beyond individual indicators and retrospectively search for processes, authentication activity, communications, and configuration changes that represent the same attack sequence.
Logging Gaps
- Verify that the relevant logs are enabled, clocks are synchronized, retention is sufficient, and correlation keys are available across endpoints, cloud services, and perimeter devices.
Priority Controls
- Patch both Chrome or other Chromium-based browsers and Windows, and confirm that browser restarts have occurred.
- Control and detect browser-related
curlexecution, execution from%TEMP%, and unfamiliar executable files. - Use email and web isolation and application control to reduce exposure and block follow-on payloads.
12. Facts / Inference / Hypothesis
Facts
- Microsoft fixed CVE-2026-81963 and CVE-2026-85880 in its September 2026 updates and identified both as exploited in the wild.
- Proofpoint reported that four espionage-focused clusters had used BlueMoon in spearphishing campaigns since August 28, 2026.
- The reported BlueMoon chain uses the V8 type-confusion flaw CVE-2026-85046 to obtain memory access inside the sandbox, CVE-2026-87491 to escape the V8 sandbox, and the Windows Advanced Local Procedure Call (ALPC) heap overflow CVE-2026-85880 to elevate privileges on older Windows builds.
- The two Chromium flaws were exploited as patch-gap zero-days: fixes existed in the upstream project but had not yet reached stable browser releases.
- The kit can retry exploitation up to five times inside a Web Worker. It fingerprints the host through a reflectively loaded DLL, elevates the renderer through local privilege escalation, and injects a
CreateProcessstub into Chrome's parent broker process. - The default command uses
curlto save a remote executable into%TEMP%and run it. Reported actors include JungleBamboo, UTA0560, UNK_LateNight, and UNK_DoubleCheck, with targeting spanning NGOs, mining, high-value individuals, aerospace and defense, and manufacturing. - Proofpoint identified debugging logs, references to a Markdown handover file in code comments, and detailed comments consistent with AI-assisted development, but cautioned that no single artifact establishes that AI was used to develop the kit.
Inference
- The investigation and detection recommendations are derived from the publicly described attack behavior. The evidence available in a particular environment depends on logging configuration and retention.
Hypothesis
No additional hypotheses. Unresolved points are listed under Unknowns and Further Investigation.
13. MITRE ATT&CK Mapping
- T1203 Exploitation for Client Execution (high confidence): Browser vulnerabilities are chained to execute code on the client.
- T1068 Exploitation for Privilege Escalation (high confidence): CVE-2026-85880 is used to elevate privileges on Windows.
- T1055 Process Injection (high confidence): A stub is injected into Chrome's parent broker process.
-
T1105 Ingress Tool Transfer (high confidence):
curlretrieves a remote payload into%TEMP%.
14. Unknowns and Further Investigation
- How multiple actors obtained the same exploit kit.
- The extent to which generative AI was used in BlueMoon's development.
- Whether CVE-2026-85880 was exploited before the observed 2026 campaigns. The DLL's 2025 compilation timestamp alone does not establish earlier exploitation.
15. Impact on SOCs and Organizations
Managing exposure across this chain requires tracking both browser and Windows patching, rather than treating updates for either product as the entire task. Organizations should account for the gap between Chromium's upstream fixes and their arrival in stable releases. During an urgent response, establish which browser versions are actually running, whether restarts have completed, and which endpoints still use older Windows builds.
SOCs should correlate the transition from Chrome to curl, execution from %TEMP%, process injection, and follow-on command-and-control traffic. Looking only for browser crashes or web indicators can miss the more consequential evidence of payload execution.
16. Audience Summaries
-
SOC: Correlate Chrome renderer and broker anomalies, browser-originated
curl, execution from%TEMP%, campaign domains, and follow-on command-and-control traffic. - Administrators: Update both Chrome or other Chromium-based browsers and Windows. Verify restarts and the versions or builds actually in use, and isolate endpoints that remain on older vulnerable Windows builds.
- Users: Avoid links in suspicious targeted emails, and complete the required restarts after browser and Windows updates.
Top comments (0)