Four Chinese espionage groups shared the same zero-day exploit kit
On September 9, Proofpoint published "Once in a BlueMoon," one of the more consequential threat intelligence reports of this year. The headline finding: four state-aligned espionage groups, the majority with a China nexus, independently adopted the same novel exploit kit within a single week of its first observed use.
That speed matters more than the individual vulnerabilities.
What is BlueMoon
BlueMoon is an exploit kit, a packaged attack chain, that combines three vulnerabilities: CVE-2026-85046 and CVE-2026-87491 in Chromium's V8 engine, and CVE-2026-85880, a heap buffer overflow in Windows ALPC that was patched on September's record-breaking Patch Tuesday.
The two Chrome flaws were zero-days when BlueMoon first appeared. The V8 defects enable sandbox escape. From there, BlueMoon fingerprints the host and executes the Windows privilege escalation. The end result is SYSTEM-level access from a single malicious link click, with no user interaction beyond opening a browser.
The final payload observed in multiple campaigns was ShadowPad, a modular backdoor long associated with Chinese intelligence contractors.
Four groups, one week
Proofpoint observed the following adoption timeline.
The first actor was Violet Typhoon (also tracked as APT31, TA412, JungleBamboo), a Beijing-backed crew that has consistently targeted NGOs and civil society. Starting August 28, Violet Typhoon used BlueMoon against US-based NGOs, mining companies, and physical commodity trading firms.
On September 2, a second group Proofpoint tracks as UNK_LateNight began using the same kit against US aerospace companies. Phishing emails were themed as business-to-business RFQ inquiries, spoofing aerospace contractors to serve the exploit chain.
A third cluster, UNK_DoubleCheck, targeted a manufacturing firm in Vietnam shortly after. A fourth actor remains unattributed but shows activity patterns consistent with state tasking.
All four campaigns ran within a seven-day window.
Why shared exploit infra changes the threat model
The traditional model for tracking state-sponsored intrusions assumes relatively siloed tooling. Groups develop or commission capabilities, use them for a campaign cycle, and retire them when burned. BlueMoon breaks that model.
Shared exploit infrastructure, where multiple independent groups leverage the same attack chain, produces several effects that defenders need to account for.
Attribution becomes harder. When four groups use the same kit, network indicators overlap. Incident responders cannot use IOCs alone to determine which state actor is behind a given intrusion.
Patch windows shrink dramatically. With multiple well-resourced groups scanning for vulnerable targets simultaneously, the time between patch release and exploitation attempts collapses from weeks to days.
The barrier to adopting cutting-edge capabilities drops. Groups that might not have the resources to develop a Chrome zero-day chain in-house can simply access one through shared infrastructure, effectively democratizing offensive capability within the state-actor tier.
What to patch right now
CVE-2026-87491 in Chrome was patched on September 8. CVE-2026-85046 was patched on September 3. CVE-2026-85880 (Windows ALPC) was addressed in the September Patch Tuesday release.
If your organization has not yet applied these updates, treat it as urgent. BlueMoon campaigns are active and the targeting breadth, NGOs, aerospace, manufacturing, commodity trading, is wide enough that sector-specific assumptions of safety are not warranted.
For detection, Proofpoint's report includes YARA rules and network indicators. The ShadowPad payload should trigger on endpoint telemetry if behavioral detection rules are current.
The bigger picture
Proofpoint's disclosure is worth reading in full. The key takeaway for security teams is not about the specific CVEs. It is about operational tempo. State-aligned actors are converging on shared tooling, adopting novel capabilities within days, and running simultaneous campaigns across multiple sectors and geographies.
The implication for defenders is straightforward: patch cadence has to match exploitation speed, and threat intelligence has to look beyond individual IOCs to the patterns of shared infrastructure and coordinated campaigns that are now the norm at the state-actor tier.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you want to discuss threat intelligence practice or attribution methodology.