Skip to content
CVEChinavulnerabilityVulnerability Research

BlueMoon and four spy groups: how an APT31 Chrome exploit kit spread to three more espionage clusters in days

3 min read
Share

The timeline

August 28, 2026: China-aligned APT31 is the first group observed using a new Chrome exploit kit named BlueMoon. Within days of that first confirmed use, three additional state-aligned espionage clusters are running the same kit against their own targets. The rapid spread prompted a joint analysis across four confirmed intrusion sets.

What BlueMoon does

BlueMoon chains two Chrome V8 vulnerabilities in sequence. CVE-2026-85046 is a type confusion flaw (CVSS 8.8) that allows remote code execution inside the Chrome sandbox via a crafted HTML page. CVE-2026-87491 is an out-of-bounds write that provides the second stage. Together they achieve code execution inside the sandbox.

Initial access comes via phishing emails directing targets to actor-controlled URLs that trigger both exploits in sequence. No user interaction beyond visiting the URL is required once the email is clicked.

Why four groups in days matters

When a well-resourced APT like APT31 deploys a new exploit kit, defenders sometimes treat that as a targeted threat relevant only to the APT's typical victim set: governments, defense contractors, aerospace, and China-adjacent diplomatic targets. The BlueMoon timeline breaks that assumption.

Three scenarios explain how the kit reached four groups so quickly. First, a shared tooling broker or underground market selling exploit kits to vetted nation-state customers. Second, deliberate capability transfer between allied state actors. Third, independent weaponization by multiple groups, which is unlikely given identical kit characteristics across the four clusters. Any of these scenarios is operationally significant. All three point to the same conclusion: the window between first nation-state use of an exploit and broad adversary availability is narrowing.

What to do now

Both CVEs are in the CISA KEV catalog with FCEB deadlines of September 23. Update Chrome to 153.0.8010.36 or later on all endpoints. Do not use September 9 (the CISA KEV addition date) as the start of your exposure window. APT31 was using this kit from August 28. Any user who was phishing-eligible on a vulnerable Chrome version between August 28 and your patch date should be treated as potentially exposed.

The calibration lesson

Attribution should not be a filter for patch priority. CVE-2026-85046 and CVE-2026-87491 were not relevant only to APT31 targets. They were relevant to every organization running a vulnerable Chrome version. The intelligence value of attribution is in understanding adversary intent and targeting patterns, not in deciding whether to apply a security patch. When a nation-state actor is using a Chrome exploit, assume it will be in four more groups' hands within a week.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you have questions about exploit kit intelligence or browser patch management.

Related articles