JungleBamboo (APT31 / Violet Typhoon)
JungleBamboo (also styled Jungle Bamboo; aliases APT31 and Violet Typhoon) is a China-linked espionage threat-actor designation documented by Volexity in September 2026. It is one of at least four-to-six Chinese state-aligned clusters identified using the identical "BlueMoon" browser exploit kit in a co-ordinated espionage push targeting US defence contractors, NGOs, mining and commodity firms, and Southeast Asian government agencies.
Attribution
| Field | Detail |
|---|---|
| Designation | JungleBamboo (APT31 / Violet Typhoon) |
| Attributed by | Volexity / Proofpoint |
| Nexus | China (state-aligned espionage) |
| Confidence | Medium โ vendor-tracked; public attribution is partial |
Activity in the BlueMoon campaign
- Used the identical "BlueMoon" browser exploit chain (CVE-2026-85046 โ CVE-2026-87491 โ CVE-2026-85880) as other China-linked clusters, indicating a shared exploit supply chain or common broker rather than independent development.
- Post-exploitation reached victims via the SUPERSTOMP loader, which installed the LONGTALE credential-stealing Chrome extension masquerading as Google Gemini.
- Campaign observed from 1 September 2026 against US defence contractors, NGOs, mining/commodity firms and Southeast Asian government agencies.
TTPs
- Browser zero-day chaining against Chrome (V8 โ WebAssembly โ Windows kernel) for full remote compromise.
- Patch-gap weaponisation: the underlying Chromium fix shipped upstream before reaching Chrome users โ a window the actors exploited within days.
- Credential-stealing browser extension as the post-exploitation payload, blending espionage collection with persistence.
Significance
JungleBamboo's use of a byte-identical exploit kit shared with other China-linked groups is the key evidence for a commercialised or brokered Chinese exploit supply chain โ the rare public convergence of multiple espionage actors on a common offensive tool. See Patch Gap Zero Day Weaponisation for the broader tradecraft.
Related Pages
- Uta0560 โ MSS-aligned actor using the same BlueMoon kit (GRIMWEDGE backdoor)
- Multiple Chinese Hacking Groups Chain Chrome Zero Day Bluemoon Exploit In Espion โ the BlueMoon campaign incident
- Cve 2026 85046, Cve 2026 87491, Cve 2026 85880 โ the chained Chrome/Windows zero-days
- Patch Gap Zero Day Weaponisation โ the patch-gap tradecraft concept