Multiple State-Aligned Threat Actors Rapidly Adopt BlueMoon Chrome and Windows Exploit Chain

· Original article ↗

Summary

Proofpoint details BlueMoon, an exploit kit chaining Chrome and Windows vulnerabilities that multiple espionage-focused actors used in spearphishing campaigns. The report covers its exploit mechanics, payloads, targets, and detection opportunities.

Key points

  • Proofpoint observed four espionage-motivated actor clusters using BlueMoon from late August through September 2026; most activity was assessed to have a suspected China nexus.
  • The chain exploits Chrome/Chromium vulnerabilities CVE-2026-85046 and CVE-2026-87491, then uses Windows kernel LPE CVE-2026-85880 to escape the renderer process on selected older Windows builds.
  • The Chrome vulnerabilities were patch-gap zero-days: upstream fixes were public before they reached stable browser releases, creating an opportunity for exploit development.
  • BlueMoon was delivered through targeted spearphishing links. Observed payloads included GemStone, a browser extension used for surveillance and credential theft, ShadowPad, and other loaders or malware.
  • Proofpoint found artifacts consistent with possible AI-assisted development, but said no single indicator conclusively establishes AI involvement.
  • Defenders can hunt for the process chain chrome.exe → cmd.exe → curl.exe → msgbox.exe, listed scheduled-task and registry artifacts, and the published ET rules and YARA rule.

Article Details

Attack Vectors
  • Targeted spearphishing links led to actor-controlled pages hosting the exploit kit, often followed by redirects to legitimate websites.
  • Lures included internship inquiries, conference outreach, vaccination registration, and aerospace business and quotation requests. Some recipients received rapport-building messages before the exploit link.
  • The browser exploit chain combined a V8 type-confusion vulnerability and V8 sandbox escape with a Windows kernel privilege-escalation vulnerability affecting older builds.
  • The kernel exploit supported builds 17763, 19041–19045, 20348, and 22000, substantially limiting eligible targets.
  • Post-exploitation shellcode injected into the parent browser process to download and execute payloads outside the renderer sandbox.
  • Payload delivery included malicious browser-extension installation, DLL-sideloading chains, encrypted payloads loaded into memory, and scheduled-task persistence.
Defensive Notes
  • Hunt for the distinctive default process tree chrome.exe -> cmd.exe -> curl.exe -> msgbox.exe.
  • Check for ChromeUpdate.exe or msgbox.exe dropped into %TEMP%.
  • Look for scheduled tasks named EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup, and GeForceService.
  • Check Chrome sessionStorage for the key v8ctf_exp_attempt.
  • Hunt for the mutex Dataupcheckinfo.
  • Investigate persistence-related writes to HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32.
  • The supplied MAL_BlueMoon_ExploitKit YARA rule matches three or more listed exploit-code or shellcode markers, including Base64 variants.
  • ET rules 2071919–2071924 cover exploit loaders and outbound beacons; rules 2071996–2072001 cover browser-extension registration, heartbeat, ingestion, screenshots, command polling, and command results.
  • Both browser vulnerabilities were already fixed in public upstream code but remained unpatched in stable browser releases during the observed activity; upstream fixes alone did not establish downstream protection.
  • The extension installer forged valid Secure Preferences HMACs and super_mac values, so those integrity checks did not prevent the observed malicious extension installation.

Indicators of compromise

TypeIndicatorContext
DOMAINairindia[.]fitSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINairliquide[.]lolSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINairproducts[.]inkUNK_LateNight BlueMoon exploit-delivery domain.
DOMAINapollohospitals[.]fitSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINattcdn[.]comTA412 exploit-delivery and payload-download domain.
DOMAINaurexdefense[.]onlineSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINbosch-sensortec[.]siteSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINbrianwilli[.]comActor-controlled UNK_DoubleCheck payload-download domain.
DOMAINchecrity[.]comShadowPad C2 domain listed in the indicator table.
DOMAINcyclokinetics[.]onlineSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINelixnovorem[.]comUNK_QuietRacket C2 domain.
DOMAINemcore[.]inkSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINepsilonsystems[.]netUNK_LateNight BlueMoon exploit-delivery domain.
DOMAINfracons[.]comC2 domain used by UNK_DoubleCheck's second-stage payload.
DOMAINgetaiexo[.]comUNK_QuietRacket C2 domain.
DOMAINhaloengines[.]netSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINjetoptera[.]coSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINjoinmacket[.]comUNK_QuietRacket BlueMoon exploit-delivery infrastructure listed as an indicator.
DOMAINlindes[.]inkSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINmsbenefit[.]comTA412 exploit-delivery and payload-download domain.
DOMAINopenlumakora[.]comUNK_QuietRacket BlueMoon exploit-delivery infrastructure listed as an indicator.
DOMAINprecipart[.]inkUNK_LateNight BlueMoon exploit-delivery domain.
DOMAINrocketlabusa[.]inkUNK_LateNight BlueMoon exploit-delivery domain.
DOMAINsecboxes[.]comTA412 exploit-delivery and payload-download domain.
DOMAINsilvustechnologies[.]onlineSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINsmxtech[.]xyzSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINsncorp[.]fitSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINspectrolab[.]fitUNK_LateNight BlueMoon exploit-delivery domain.
DOMAINtcomlp[.]onlineSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
DOMAINvelodynaity[.]comUNK_QuietRacket C2 domain.
DOMAINworldview[.]fitSuspected UNK_LateNight BlueMoon delivery domain based on shared IP resolution.
EMAILdewiinpermata@outlook[.]comUNK_QuietRacket phishing sender address listed as an indicator.
EMAILditjenpajakri2026@outlook[.]comUNK_QuietRacket phishing sender address listed as an indicator.
EMAILfaizus123@outlook[.]comUNK_QuietRacket phishing sender address listed as an indicator.
EMAILfaizus123@proton[.]meUNK_QuietRacket phishing sender address listed as an indicator.
EMAILfirda[.]kemkes@outlook[.]comUNK_QuietRacket phishing sender address listed as an indicator.
EMAILjeannifer[.]suryajaya@outlook[.]comUNK_QuietRacket phishing sender address listed as an indicator.
EMAILlaylowthiago@gmail[.]comUNK_LateNight phishing sender address listed as an indicator.
EMAILmariedubois1917@outlook[.]comUNK_LateNight phishing sender address listed as an indicator.
EMAILradhikadas07@outlook[.]comUNK_QuietRacket phishing sender address listed as an indicator.
EMAILreallifetalktv2@gmail[.]comUNK_LateNight phishing sender address listed as an indicator.
EMAILsiti[.]nurhaliza2026@outlook[.]comUNK_QuietRacket phishing sender address listed as an indicator.
EMAILsusan[.]thomas[.]90@outlook[.]comUNK_LateNight phishing sender address listed as an indicator.
EMAILzfg[.]rc[.]420@gmail[.]comUNK_LateNight phishing sender address listed as an indicator.
HOSTNAME1a062f4982564d6d19a76884ce8bcbb6[.]r2[.]cloudflarestorage[.]comSpecific Cloudflare R2 bucket used by the Rust loader to download a second DLL-sideloading set.
HOSTNAMEasianstudies[.]secboxes[.]comTA412 BlueMoon exploit-page hostname.
HOSTNAMEblack-flower-9250[.]v93xdd5g[.]workers[.]devUNK_QuietRacket second C2 channel; no payloads were observed served from it.
HOSTNAMEdaoahueb[.]workers[.]devUNK_QuietRacket payload-download hostname.
HOSTNAMEdata[.]attcdn[.]comTA412 BlueMoon exploit-page hostname.
HOSTNAMEdns[.]elixnovorem[.]comTXT lookup hostname whose encrypted record resolved to UNK_QuietRacket payload infrastructure.
HOSTNAMEdns[.]getaiexo[.]comTXT lookup hostname used by UNK_QuietRacket's recurring C2 loop.
HOSTNAMEdns[.]velodynaity[.]comUNK_QuietRacket C2 TXT lookup hostname listed as an indicator.
HOSTNAMEeduac[.]workers[.]devUNK_QuietRacket exploit-delivery, download, and C2 hostname.
HOSTNAMEevidence[.]msbenefit[.]comTA412 BlueMoon exploit-page hostname.
HOSTNAMEextension-management-portal[.]centerfjdr658[.]workers[.]devGemStone browser-extension C2 hostname.
HOSTNAMEextension-management-portal[.]kmjukilo-lkjh[.]workers[.]devGemStone browser-extension C2 hostname.
HOSTNAMEhomepage[.]brianwilli[.]comUNK_DoubleCheck DLL-sideloading payload-download hostname.
HOSTNAMEmailtbox[.]workers[.]devUNK_DoubleCheck BlueMoon delivery infrastructure listed as an indicator.
HOSTNAMEmaterials-project[.]secboxes[.]comTA412 BlueMoon exploit-page hostname.
HOSTNAMEms[.]checrity[.]comShadowPad HTTPS C2 hostname used in UNK_LateNight activity.
HOSTNAMEproject[.]secboxes[.]comTA412 BlueMoon exploit-page hostname.
HOSTNAMEpublish[.]openlumakora[.]comUNK_QuietRacket BlueMoon exploit-delivery hostname.
HOSTNAMErecommendation-letter[.]secboxes[.]comTA412 BlueMoon exploit-page hostname.
HOSTNAMEroyal-surf-a2e2[.]daoahueb[.]workers[.]devServed encrypted HTML containing an in-memory .NET payload that established UNK_QuietRacket persistence.
HOSTNAMEv93xdd5g[.]workers[.]devUNK_QuietRacket C2 hostname listed as an indicator.
HOSTNAMEvncdc[.]mailtbox[.]workers[.]devUNK_DoubleCheck BlueMoon delivery hostname.
HOSTNAMEwcce[.]joinmacket[.]comUNK_QuietRacket BlueMoon exploit-delivery hostname.
HOSTNAMEyhv41nji[.]workers[.]devUNK_QuietRacket BlueMoon exploit-delivery hostname.
IPV479[.]133[.]56[.]90Fallback ShadowPad C2 server.
SHA256295fc584f75e94108c9be945977db33ed80421f5d374eab188587c911dffd915UNK_LateNight msgbox.exe ShadowPad loader.
SHA256353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98eeGemStone background.js malicious extension service worker.
SHA2563594ad58fb6217fafe9839e53999a90608c2e9f335fa20aece3d53f8c0802726UNK_DoubleCheck SysPr.prx encrypted payload blob.
SHA2563ec3151d8d1278ed966941ac89ea495ef6a80c70613dd9138cc85fc28c9df432UNK_DoubleCheck krita.dll infection-chain artifact.
SHA2566e6378d8d404166da89d982e80bc52e19a3f677201258dec1775f100a027a92dMalicious artifact listed in the UNK_DoubleCheck indicator table; individual filename not disclosed.
SHA256779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096dTA412 driver-html.js BlueMoon exploit JavaScript.
SHA2567d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288TA412 ChromeUpdate.exe or msgbox.exe extension installer.
SHA2568453c42904b7b2fea5671b7bff06b2d937632ae29545fd11bc13095627a2805fUNK_QuietRacket Indostartupexpo.js BlueMoon exploit JavaScript.
SHA25687b6b24c06f99900a8aa579caedee1e402015884c925a98dcfb0fb38dfa2de22UNK_QuietRacket GFExperienceUpdate.dll malicious loader.
SHA256a4a6a04d85eca8d584d939d2437c85a4f291207d8042f2ec002838e336b72ef5UNK_LateNight Index.js BlueMoon exploit JavaScript.
SHA256ac6806c89e294f390838cb07c015dabec1c8ada06ce5161a0ad50b8a72828141UNK_DoubleCheck calibre-launcher.dll infection-chain artifact.
SHA256ac6bbc4b1f1c62e308781329183a46e18f454c27e66bffa09f343b53ac622b69UNK_DoubleCheck font-01.js BlueMoon exploit JavaScript.
SHA256b34802a646fc4a8f07ffa09a5fda8bf7327446b22e3d7bb5163dafa1e2a8bb2bUNK_QuietRacket Loader.js BlueMoon exploit JavaScript.
SHA256bc7d24f5cf8937b334966201bdcce8ca9bab6ec5889d40a399d4094dcad73360UNK_LateNight mctsetup64.dll infection-chain artifact.
SHA256e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004TA412 dist.zip malicious browser-extension archive.
SHA256f3c64014221a58f3fde88e562662dbd5a1b3dd2b59c86e9e2bc5cb8f671664e7UNK_QuietRacket GFExperienceUpdate.dll malicious loader.
SHA256ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782bTA412 ChromeUpdate.exe or msgbox.exe extension installer.
URLhxxps[:]//1a062f4982564d6d19a76884ce8bcbb6[.]r2[.]cloudflarestorage[.]com/datago/krita[.]dllSpecific cloud-hosted DLL URL for UNK_DoubleCheck's second DLL-sideloading set.
URLhxxps[:]//1a062f4982564d6d19a76884ce8bcbb6[.]r2[.]cloudflarestorage[.]com/datago/krita[.]exeSpecific cloud-hosted executable URL for UNK_DoubleCheck's second DLL-sideloading set.
URLhxxps[:]//1a062f4982564d6d19a76884ce8bcbb6[.]r2[.]cloudflarestorage[.]com/datago/SysPr[.]prxSpecific cloud-hosted payload blob URL for UNK_DoubleCheck's second DLL-sideloading set.
URLhxxps[:]//api-prod[.]secboxes[.]com/downloadTA412 payload download URL listed in the indicator table.
URLhxxps[:]//app[.]eduac[.]workers[.]dev/ServiceUNK_QuietRacket DLL-sideloading pair download URL.
URLhxxps[:]//app[.]eduac[.]workers[.]dev/UpdateacUNK_QuietRacket DLL-sideloading pair download URL.
URLhxxps[:]//download[.]secboxes[.]com/dist[.]zipTA412 malicious extension archive download URL.
URLhxxps[:]//evidence[.]msbenefit[.]com/msgbox[.]exeTA412 post-exploitation installer download URL.
URLhxxps[:]//homepage[.]brianwilli[.]com/d/{wint[.]exe,calibre-launcher[.]dll,85rY[.]dat,SysPr[.]prx}Literal curl URL expression used by UNK_DoubleCheck to download four infection-chain files.
URLhxxps[:]//homepage[.]brianwilli[.]com/d/85rY[.]datUNK_DoubleCheck infection-chain artifact download URL.
URLhxxps[:]//homepage[.]brianwilli[.]com/d/calibre-launcher[.]dllUNK_DoubleCheck DLL-sideloading payload download URL.
URLhxxps[:]//homepage[.]brianwilli[.]com/d/SysPr[.]prxUNK_DoubleCheck encrypted payload blob download URL.
URLhxxps[:]//homepage[.]brianwilli[.]com/d/wint[.]exeUNK_DoubleCheck DLL-sideloading executable download URL.
URLhxxps[:]//project[.]secboxes[.]com/ChromeUpdate[.]exeTA412 post-exploitation installer download URL.
URLhxxps[:]//recommendation-letter[.]secboxes[.]com/ChromeUpdate[.]exeTA412 post-exploitation installer download URL.
URLhxxps[:]//small-union-7018[.]daoahueb[.]workers[.]dev/UNK_QuietRacket DLL-sideloading pair download URL.
URLhxxps[:]//snowy-block-ae0a[.]daoahueb[.]workers[.]dev/UNK_QuietRacket DLL-sideloading pair download URL.
URLhxxps[:]//zki0y83[.]msbenefit[.]com/feedTA412 download URL listed in the indicator table.

MITRE ATT&CK

T1016.001 · Internet Connection DiscoveryGemStone queried public IP identification services to incorporate the victim's public IP into its registration identifier.T1027 · Obfuscated Files or InformationBlueMoon variants encoded or obfuscated components; subsequent payloads used XOR, AES, RC4, Base64, and ChaCha20.T1036 · MasqueradingGemStone masqueraded as an AI-powered browsing companion by Google Gemini.T1040 · Network SniffingThe ShadowPad payload was reported to sniff network traffic.T1041 · Exfiltration Over C2 ChannelGemStone exfiltrated keystrokes, cookies, storage entries, navigation events, and session metadata through its C2 ingest endpoint, with screenshots uploaded separately.T1053.005 · Scheduled TaskPersistence used scheduled tasks including EdgeCore_AutoUpdate and GeForceService.T1055 · Process InjectionBlueMoon wrote executable code into the parent browser process and started a remote thread; the ShadowPad loader also injected decrypted contents into processes such as wmpnetwk.exe.T1056.001 · KeyloggingGemStone injected a recorder that captured keydown, input, change, and paste events across eligible tab frames.T1059.003 · Windows Command ShellPost-exploitation commands used cmd.exe to invoke curl and run downloaded executables.T1068 · Exploitation for Privilege EscalationThe kernel exploit enabled SeDebugPrivilege in the renderer token using CVE-2026-85880.T1070.004 · File DeletionThe UNK_LateNight loader immediately overwrote its TMP payload file after reading and decrypting it.T1071.001 · Web ProtocolsGemStone used HTTP C2 endpoints, and ShadowPad beaconed over HTTPS using a binary C2 protocol.T1071.004 · DNSUNK_QuietRacket repeatedly retrieved encrypted TXT records through DNS-over-HTTPS to resolve its C2 infrastructure.T1082 · System Information DiscoveryThe reconnaissance DLL collected Windows version and build information and the kernelbase.dll build version to gate exploitation.T1105 · Ingress Tool TransferBlueMoon downloaded operator-provided executables, and subsequent loaders fetched malicious extensions and additional payload sets.T1112 · Modify RegistryThe UNK_LateNight chain stored a payload copy in the registry, and UNK_DoubleCheck wrote a CLSID InprocServer32 key for persistence.T1113 · Screen CaptureGemStone captured the visible tab on command or when monitored keywords were found.T1140 · Deobfuscate/Decode Files or InformationLoaders decrypted encrypted TMP and SysPr.prx payloads and decoded encrypted HTML content before execution.T1176.001 · Browser ExtensionsTA412 installed GemStone as a malicious Chromium browser extension by rewriting browser preferences with forged integrity values.T1203 · Exploitation for Client ExecutionBlueMoon exploited V8 type confusion and a V8 sandbox escape after recipients opened exploit-delivery links.T1539 · Steal Web Session CookieGemStone's CAPTURE_COOKIES command collected cookies from every accessible cookie store.T1562.001 · Disable or Modify ToolsShadowPad unhooked 20 network-monitoring functions to remain stealthy.T1566.002 · Spearphishing LinkAll four clusters sent targeted phishing emails containing links to BlueMoon exploit pages.T1574.002 · DLL Side-LoadingUNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket delivered DLL-sideloading pairs.T1620 · Reflective Code LoadingBlueMoon reflectively loaded reconnaissance and kernel-exploit DLLs; UNK_QuietRacket also loaded a decrypted .NET assembly into memory.

CVE

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles