Four Hacking Groups Utilized BlueMoon Exploit Kit
The exploit kit chained three browser and kernel vulnerabilities to achieve system-level access before patches were issued.
Updated on Sept. 20, 2026 in Cybersecurity

Live Poll
Do you trust that current software security practices are keeping pace with new AI-driven hacking threats?
Proofpoint researchers identified the BlueMoon exploit kit, which four hacking groups used to target organizations beginning August 28, 2026. The kit leveraged three vulnerabilities to grant attackers system-level permissions.
Why it matters
This campaign highlights how attackers are leveraging artificial intelligence to identify and weaponize supply chain gaps in Chromium-based browsers at an accelerated pace. The strategy demonstrates a shift toward more complex, multi-stage exploit chains that bypass standard sandboxing protections.
The BlueMoon kit chains CVE-2026-85046 in Chrome and CVE-2026-85880 in Windows. These flaws allow for system-level remote code execution through the combination of type confusion and sandbox escape bugs.
The players
Proofpoint
A cybersecurity firm specializing in threat intelligence, malware analysis, and cloud-based email security solutions.
TA412
A hacking group observed targeting organizations with advanced persistent threats and custom exploit kits.
The details
BlueMoon functions by weaponizing a patch gap in the Chromium supply chain to deliver malware. It combines two vulnerabilities in the V8 JavaScript engine—the software component that executes code in browsers—with a local privilege escalation flaw in the Windows kernel, the core operating system layer. This chain allows attackers to escape the browser sandbox, a security mechanism that isolates running processes, to gain full system-level permissions.
Timeline
August 28, 2026: The hacking group TA412 began using the BlueMoon exploit kit.
August 2026: Three additional hacking groups initiated campaigns using the kit.
September 16, 2026: Security research on the exploit kit was disclosed.
September 17, 2026: Patches for all three vulnerabilities were issued within 24 hours.
The Tech Race
The emergence of BlueMoon marks a departure from traditional single-vulnerability exploits by utilizing complex chains to accelerate the attack surface. This development follows a pattern set by the Chromium vulnerability disclosure and patching lifecycle, specifically targeting the window before organizations can implement updates.
Users should verify that their Chromium-based browsers and Windows operating systems have been updated to the latest available versions released after September 17, 2026. This is the primary defense against the BlueMoon kit, as the exploits rely on the absence of these specific security patches.
The takeaway
The sophistication of BlueMoon illustrates that attackers are increasingly using automated tools to capitalize on the brief delay between vulnerability disclosure and deployment. Organizations should monitor their patch management velocity as the next key milestone in defending against similar chained-exploit campaigns.
What happens next
Security teams should track the rollout of browser updates following the September 17, 2026, patch release to ensure all Chromium-based systems are protected against CVE-2026-85046 and CVE-2026-85880.
Further reading
For more on evolving threat vectors, visit the Cybersecurity section.
Live Poll
Do you trust that current software security practices are keeping pace with new AI-driven hacking threats?






