{"id":1559,"date":"2026-09-11T12:21:54","date_gmt":"2026-09-11T06:51:54","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1559"},"modified":"2026-09-14T15:19:42","modified_gmt":"2026-09-14T09:49:42","slug":"bluemoon-exploit-kit-targets-chrome-and-windows-endpoints","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/","title":{"rendered":"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints"},"content":{"rendered":"<p>Security researchers have identified a new BlueMoon exploit kit that chains two Chrome vulnerabilities with a Windows privilege escalation flaw. Proofpoint first observed China-aligned group APT31 using it on August 28, 2026. Three more espionage clusters adopted it within days.<\/p>\n<p>The rapid reuse matters because a fully weaponized Chrome exploit chain has historically been rare and costly to build. Proofpoint noted the kit moved from single-actor to multi-actor use within about a week, despite high detection signals. That speed suggests shared tooling access or a lower barrier to building this capability.<\/p>\n<p>For enterprise defenders, the chain turns one clicked link into full code execution and elevated privileges. It bypasses browser <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-sandboxing\/\">sandboxing<\/a> and reaches Windows kernel-adjacent territory, raising the stakes beyond a typical browser bug.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>Inside the BlueMoon attack chain<\/h2>\n<p>A <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-phishing\/\">phishing<\/a> email leads the target to an actor-controlled link. From there, BlueMoon runs through distinct technical steps rather than one mechanism.<\/p>\n<ul>\n<li><strong>Browser exploitation:<\/strong> The kit triggers <a href=\"https:\/\/www.tenable.com\/cve\/CVE-2026-85046?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=bluemoon_exploit_kit\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-85046<\/a>, a Chrome V8 type confusion bug, then <a href=\"https:\/\/www.tenable.com\/cve\/CVE-2026-87491?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=bluemoon_exploit_kit\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-87491<\/a>, a V8 out-of-bounds flaw enabling sandbox escape. Chained together, they give code execution outside the sandbox.<\/li>\n<li><strong>Host fingerprinting:<\/strong> A reflectively loaded DLL profiles the Windows host. The kit&#8217;s JavaScript uses this to decide whether the privilege escalation step is worth attempting.<\/li>\n<li><strong><a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-privilege-escalation\/\">Privilege escalation<\/a>:<\/strong> A second reflectively loaded DLL exploits CVE-2026-85880, a heap-based buffer overflow in Windows ALPC, to elevate the Chrome renderer process.<\/li>\n<li><strong>Payload execution:<\/strong> The injector shellcode injects a CreateProcess stub into the Chrome broker process. The default command downloads and runs a remote executable via curl.<\/li>\n<\/ul>\n<p>Both Chrome flaws were patch-gap zero-days. Chromium&#8217;s upstream source already had fixes, but they hadn&#8217;t reached stable Chrome when attackers exploited them. This suggests the developer tracked public Chromium commits to weaponize the gap before vendors shipped updates.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-best-practices.jpg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Cybersecurity Best Practices for Businesses to Adopt in 2026<\/h4><p>Stop repeating basic mistakes. Learn 2026's real cybersecurity survival strategy now.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/cybersecurity-best-practices-2026-guide\/\" aria-label=\"Cybersecurity Best Practices for Businesses to Adopt in 2026\"><\/a><\/div><\/div><\/div>\n<h2>Four distinct threat clusters, one shared kit<\/h2>\n<p>Proofpoint tracked four clusters using BlueMoon within roughly a week, each with its own targeting and payload. China-nexus evidence varies by cluster, so each is stated separately.<\/p>\n<ul>\n<li><strong>APT31 (from August 28, 2026):<\/strong> Confirmed China-aligned. Targeted U.S. NGOs, mining companies, and commodity trading firms via spear-phishing. The chain delivers a loader that installs a fake &#8220;Google Gemini&#8221; browser extension, bypassing integrity checks via a technique called GhostChrome-X. The resulting backdoor, GemStone, steals credentials and enables browser surveillance over C2.<\/li>\n<li><strong>UNK_LateNight (from September 2, 2026):<\/strong> China-aligned per Proofpoint. Targeted U.S. aerospace companies, deploying the ShadowPad backdoor via DLL sideloading.<\/li>\n<li><strong>UNK_DoubleCheck (from September 2, 2026):<\/strong> No stated nexus. Targeted a Vietnamese manufacturer, hosting BlueMoon on a Cloudflare Workers domain and sideloading a Rust binary that fetches a second sideloading pair from a Cloudflare R2 bucket.<\/li>\n<li><strong>UNK_QuietRacket (from September 3, 2026):<\/strong> China-aligned per Proofpoint. Targeted government, consulting, and financial firms in Indonesia and Singapore. This variant sideloads a DLL that runs a .NET assembly in memory, which creates a scheduled task for persistence.<\/li>\n<\/ul>\n<p>Proofpoint said most activity shows a suspected China nexus but cautioned BlueMoon may not be exclusive to China-aligned actors, since some usage remains unattributed. Extensive logging, verbose code comments, and repeated v8CTF references suggest possible AI-assisted development. Proofpoint said it&#8217;s unconfirmed whether this reflects genuine bounty research or an attempt to bypass AI model guardrails.<\/p>\n<h2>Patch status and federal remediation deadlines<\/h2>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 28.4355%; text-align: left;\"><strong>Vulnerability<\/strong><\/th>\n<th style=\"width: 36.8922%; text-align: left;\"><strong>Type<\/strong><\/th>\n<th style=\"width: 33.6152%; text-align: left;\"><strong>Patch Status<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 28.4355%;\">CVE-2026-85046<\/td>\n<td style=\"width: 36.8922%;\">Chrome V8 type confusion<\/td>\n<td style=\"width: 33.6152%;\">Patched by Google on September 3, 2026<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 28.4355%;\">CVE-2026-87491<\/td>\n<td style=\"width: 36.8922%;\">Chrome V8 out-of-bounds bug, sandbox escape<\/td>\n<td style=\"width: 33.6152%;\">Patched by Google on September 8, 2026<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 28.4355%;\">CVE-2026-85880<\/td>\n<td style=\"width: 36.8922%;\">Windows ALPC heap-based buffer overflow (LPE)<\/td>\n<td style=\"width: 33.6152%;\">Patched by Microsoft in its September 8, 2026 Patch Tuesday update<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>CISA added all three CVEs to its Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies must remediate CVE-2026-85046 by September 18, <a href=\"https:\/\/www.tenable.com\/cve\/CVE-2026-85880?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=bluemoon_exploit_kit\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-85880<\/a> by September 22, and CVE-2026-87491 by September 23, 2026.<\/p>\n<p>Patching closes the entry point. It does not remove anything an attacker already installed through that entry point. Organizations need to check for persistence artifacts separately from confirming the patches are applied.<\/p>\n<h2>Post-exploitation indicators to hunt for<\/h2>\n<p>Security teams should check managed endpoints for the following artifacts, which can persist after the browser and OS are patched:<\/p>\n<ul>\n<li><strong>Process tree:<\/strong> chrome.exe spawning cmd.exe, then curl.exe, then msgbox.exe<\/li>\n<li><strong>File:<\/strong> ChromeUpdate.exe or msgbox.exe in the Windows %TEMP% folder<\/li>\n<li><strong>Folder:<\/strong> C:\\Users\\Public\\stomp_ext<\/li>\n<li><strong>Scheduled tasks:<\/strong> EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup, or GeForceService<\/li>\n<li><strong>Mutex:<\/strong> Dataupcheckinfo<\/li>\n<li><strong>Registry key:<\/strong> HKCU\\SOFTWARE\\Classes\\CLSID{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\\InprocServer32<\/li>\n<\/ul>\n<p>Proofpoint has also published detection signatures for the kit&#8217;s JavaScript loader and its C2 traffic.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download this cybersecurity kit for blueprints, frameworks, checklists, policy templates, and guides securing your enterprise.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Where Hexnode fits<\/h2>\n<p>The BlueMoon exposure centers on Chrome and Windows, but Hexnode&#8217;s endpoint coverage extends further. UEM manages configuration compliance across Windows, Linux, macOS, Android, and iOS, and automated OS and third-party application patch management (including Chrome) for Windows and macOS, while XDR investigates what happened after exploitation on managed endpoints.<\/p>\n<h3>UEM<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> flags devices still running vulnerable browser or OS builds.<\/li>\n<li>Pushes emergency patch policies for OS updates and third-party browsers like Chrome across Windows and macOS endpoints.<\/li>\n<\/ul>\n<h3>XDR<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> investigates suspicious activity on managed endpoints, primarily Windows and macOS.<\/li>\n<li>Surfaces post-exploitation behavior, such as chrome.exe spawning cmd.exe or curl.exe, by mapping endpoint activity to MITRE ATT&amp;CK tactics.<\/li>\n<li>Provides one-click remediation capabilities, allowing security operations to isolate compromised endpoints or terminate malicious process trees instantly.<\/li>\n<li>Complements, rather than replaces, vendor patching and the artifact-level hunting described above.<\/li>\n<\/ul>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is the BlueMoon exploit kit?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>BlueMoon is an exploit kit that chains two Google Chrome V8 vulnerabilities with a Windows privilege escalation bug to achieve code execution and elevated access on a targeted endpoint.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Has BlueMoon been patched?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Google and Microsoft have patched all three vulnerabilities in the chain as of September 2026, and CISA has added them to its Known Exploited Vulnerabilities catalog with federal remediation deadlines.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should security teams check for after patching?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Teams should hunt for post-exploitation artifacts such as specific scheduled task names, registry keys, and process trees, since patching removes the entry point but not anything already installed through it.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>BlueMoon shows how quickly a rare capability, a fully weaponized Chrome exploit chain, can spread across unrelated threat actors once it exists. Patching the browser and the OS closes the entry point, but four separate clusters already used that entry point to install different persistence mechanisms.<\/p>\n<p>Enterprise security teams should treat this as two separate jobs: confirm patches are deployed everywhere, and hunt for the artifacts left behind before those patches went out.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay ahead of active exploit chains.<\/h5><p>Get threat intelligence and patch alerts delivered to your inbox.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers have identified a new BlueMoon exploit kit that chains two Chrome vulnerabilities with&#8230;<\/p>\n","protected":false},"author":5,"featured_media":1599,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12,16],"class_list":["post-1559","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zero-day","category-windows","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>BlueMoon Exploit Kit Targets Chrome and Windows Endpoints<\/title>\n<meta name=\"description\" content=\"BlueMoon exploit kit chains two Chrome V8 zero-days with a Windows flaw. Learn how APT31 and three other espionage clusters exploited it.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints\" \/>\n<meta property=\"og:description\" content=\"BlueMoon exploit kit chains two Chrome V8 zero-days with a Windows flaw. Learn how APT31 and three other espionage clusters exploited it.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-11T06:51:54+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-14T09:49:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/bluemoon-exploit-kit.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints\",\"datePublished\":\"2026-09-11T06:51:54+00:00\",\"dateModified\":\"2026-09-14T09:49:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/\"},\"wordCount\":1148,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/bluemoon-exploit-kit.jpeg?format=webp\",\"articleSection\":[\"Zero-Day\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/\",\"name\":\"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/bluemoon-exploit-kit.jpeg?format=webp\",\"datePublished\":\"2026-09-11T06:51:54+00:00\",\"dateModified\":\"2026-09-14T09:49:42+00:00\",\"description\":\"BlueMoon exploit kit chains two Chrome V8 zero-days with a Windows flaw. Learn how APT31 and three other espionage clusters exploited it.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/bluemoon-exploit-kit.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/bluemoon-exploit-kit.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"bluemoon exploit kit\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints","description":"BlueMoon exploit kit chains two Chrome V8 zero-days with a Windows flaw. Learn how APT31 and three other espionage clusters exploited it.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/","og_locale":"en_US","og_type":"article","og_title":"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints","og_description":"BlueMoon exploit kit chains two Chrome V8 zero-days with a Windows flaw. Learn how APT31 and three other espionage clusters exploited it.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-11T06:51:54+00:00","article_modified_time":"2026-09-14T09:49:42+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/bluemoon-exploit-kit.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints","datePublished":"2026-09-11T06:51:54+00:00","dateModified":"2026-09-14T09:49:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/"},"wordCount":1148,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/bluemoon-exploit-kit.jpeg?format=webp","articleSection":["Zero-Day","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/","url":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/","name":"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/bluemoon-exploit-kit.jpeg?format=webp","datePublished":"2026-09-11T06:51:54+00:00","dateModified":"2026-09-14T09:49:42+00:00","description":"BlueMoon exploit kit chains two Chrome V8 zero-days with a Windows flaw. Learn how APT31 and three other espionage clusters exploited it.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/bluemoon-exploit-kit.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/bluemoon-exploit-kit.jpeg?format=webp","width":1340,"height":700,"caption":"bluemoon exploit kit"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/bluemoon-exploit-kit-targets-chrome-and-windows-endpoints\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"BlueMoon Exploit Kit Targets Chrome and Windows Endpoints"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1559","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1559"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1559\/revisions"}],"predecessor-version":[{"id":1622,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1559\/revisions\/1622"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1599"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1559"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}