Proofpoint published Once in a BlueMoon on September 9, 2026: multiple espionage-motivated threat actors rapidly adopted a shared exploit kit that chains a Chromium V8 remote code execution bug, a V8 sandbox escape, and a Windows kernel local privilege escalation. Proofpoint tracks the kit as BlueMoon. The Record’s same-day writeup frames at least four clusters, most China-linked, hitting U.S. defense contractors, NGOs, and Southeast Asian targets with the same underlying code.
The browser stage abuses CVE-2026-85046 (V8 type confusion in TurboFan/Maglev). Chromium’s fix landed in public source on August 7, 2026, but stable Chrome did not ship it until about September 3 — a roughly four-week patch gap Proofpoint says attackers used to weaponize the public diff. A second V8 sandbox escape (no CVE assigned, per Proofpoint) then elevates out of the renderer. The Windows stage is CVE-2026-85880, an ALPC/WNF kernel LPE Microsoft also flagged as exploited in the wild on September Patch Tuesday — gated in BlueMoon to older Windows builds (Win10 1809–22H2, Server 2019/2022, Win11 21H2). Default post-exploit is blunt: chrome.exe → cmd.exe → curl.exe into %TEMP%, then actor malware.
First observed adopter: China-aligned TA412 (JungleBamboo / Violet Typhoon / APT31) from August 28, targeting U.S. NGOs, mining, and commodity traders with internship and AAS-in-Asia lures, then installing GemStone — a malicious Chromium extension masquerading as Google Gemini for browser surveillance and credential theft. UNK_LateNight (suspected China-aligned) hit U.S. aerospace/defense with RFQ lures and delivered ShadowPad. UNK_DoubleCheck (unattributed espionage) hit a Vietnamese manufacturer via a compromised SEA government mailbox. UNK_QuietRacket (suspected China-aligned) hit government, consulting, and finance in Indonesia and Singapore with conference lures. Proofpoint says the kit code is practically identical across actors — not parallel development — and flags possible AI-assisted build artifacts (verbose debug comments, markdown handover refs, v8CTF framing). Victim count: Undisclosed; this read uses Proofpoint’s cluster list only.
Underwrite sheet — sourced only: BlueMoon = CVE-2026-85046 + V8 sandbox escape + CVE-2026-85880; TA412 / UNK_LateNight / UNK_DoubleCheck / UNK_QuietRacket; GemStone fake-Gemini extension; ShadowPad on aerospace; ~4-week Chromium patch gap; Microsoft already patched CVE-2026-85880 this Patch Tuesday. Primary is Proofpoint’s report. The Record for the multi-group framing. Patch Chromium estates and the Windows KEV rows; Proofpoint left the nation-state procurement chain question open.
