Chinese espionage groups swarm to exploit triple-link chain of zero-days
Get our latest cybersecurity news first on Google.
Proofpoint researchers have spotted at least four state-aligned threat groups chain a trio of zero-day vulnerabilities to conduct espionage on various targets of interest to China’s government since late August.
The Chinese espionage group that Proofpoint tracks as TA412, also known as Violet Typhoon and APT31, struck first, exploiting the chain of vulnerabilities Aug. 28. At least three additional espionage threat groups followed suit, exploiting the same vulnerabilities in subsequent waves of attacks days later, researchers said.
The exploit chain Proofpoint calls BlueMoon targets Chrome, Chromium-based browsers and Microsoft Windows. It allows attackers to run code in the browser’s sandbox, escape the sandbox and gain system privileges to access a targeted machine, said Mark Kelly, staff threat researcher at Proofpoint.
“All three vulnerabilities were exploited before patches were available to the public,” he said.
The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Tuesday in Windows Advanced Local Procedure Call.
“While the V8 vulnerabilities were known and fixed in Chromium source code, they were not yet patched in the latest publicly available browsers at the time of the activity, meaning they effectively functioned as zero-days in those products,” Kelly said.
Proofpoint said the exploit kit developer likely reverse engineered the publicly available Chromium patches to weaponize the browser exploit chain during that gap.
With a limited group of organizations exposed to all three vulnerabilities, attackers moved quickly and likely rushed development to target a narrow pool of potential targets. “In all observed cases, the infrastructure used for exploit delivery was created on the same day as — or in the days immediately preceding — the associated campaigns,” Proofpoint wrote in a threat intelligence report.
APT31, a group that’s committed espionage on behalf of China’s Ministry of State Security, including seven Chinese nationals indicted by the Justice Department in 2024, dropped various lures containing the exploit chain loader in phishing emails targeting non-governmental organizations, mining companies and commodity trading firms in the United States.
The phishing link installed a malicious browser extension disguised as Google Gemini on targeted machines, enabling attackers to surveil browser activity, steal credentials and execute commands, according to Proofpoint.
Other distinct threat groups have also used the BlueMoon exploit chain with some slight technical changes and variances in targeting.
“Proofpoint observed BlueMoon usage as recently as Sept. 8,” Kelly said. “The activity peaked Sept. 2-3 immediately prior to the Chrome patch being released and has continued intermittently since then.”
A China-aligned espionage threat group Proofpoint tracks as UNK_LateNight targeted multiple U.S. aerospace companies Sept. 2. Researchers also that day observed UNK_DoubleCheck, a suspected espionage-motivated threat group targeting Vietnamese manufacturing organizations with emails from a compromised Southeast Asian government account.
Researchers said UNK_QuietRacket, another espionage group aligned with China, targeted government, consulting and financial sector organizations in Indonesia and Singapore Sept. 3.
Proofpoint has directly observed fewer than 20 organizations targeted globally thus far, but Kelly said the true number of impacted organizations is likely much higher.
While Proofpoint attributes most of the observed attacks to Chinese espionage groups, attackers of other origins and motivations could strike soon as well.
“Given its ease of adoption, we expect the exploit kit is likely to proliferate further and be adopted by additional espionage-motivated and financially motivated threat actors as patched versions are fully rolled out across all Chromium-based browsers,” Kelly said.
Latest Podcasts
Government
FTC rescinds policy requiring health apps to notify customers after a breach
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Technology
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Wyden seeks upgraded NSA security guidance on commercial VPN use
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Reproduced in full under licence from CyberScoop. © CyberScoop. Written by Matt Kapko.
At a glance
- Severity
- Mediumfrom category and source signals; no CVSS referenced
- Exploitation
- No vulnerabilities referenced
- Vulnerabilities
- None referenced
- Vendors & products
- None named
- Threat actors & malware
- None named
- Industries
- Not industry-specific
- Coverage
- 1 outlet· first seen 2026-09-09 21:17 UTC
- Priority
- 42/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.
Coverage
One outlet has carried this so far.
2026-09-09 21:17 UTC
Related stories
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The Hacker News · 2026-09-12
- GitLab security advisory (AV26-917)
Canadian Centre for Cyber Security · 2026-09-11
- Hackers abused Claude to extract secrets from 1.8M Android apps
BleepingComputer · 2026-09-11
- n8n security advisory (AV26-916)
Canadian Centre for Cyber Security · 2026-09-11
- Progress security advisory (AV26-915)
Canadian Centre for Cyber Security · 2026-09-11