Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [apt-group, threat-actor, espionage, china, chrome-zero-day] ยท confidence: medium ยท affected_sectors: [defence, government, technology] ยท au_impact: true

JungleBamboo (APT31 / Violet Typhoon)

JungleBamboo (also styled Jungle Bamboo; aliases APT31 and Violet Typhoon) is a China-linked espionage threat-actor designation documented by Volexity in September 2026. It is one of at least four-to-six Chinese state-aligned clusters identified using the identical "BlueMoon" browser exploit kit in a co-ordinated espionage push targeting US defence contractors, NGOs, mining and commodity firms, and Southeast Asian government agencies.

Attribution

Field Detail
Designation JungleBamboo (APT31 / Violet Typhoon)
Attributed by Volexity / Proofpoint
Nexus China (state-aligned espionage)
Confidence Medium โ€” vendor-tracked; public attribution is partial

Activity in the BlueMoon campaign

  • Used the identical "BlueMoon" browser exploit chain (CVE-2026-85046 โ†’ CVE-2026-87491 โ†’ CVE-2026-85880) as other China-linked clusters, indicating a shared exploit supply chain or common broker rather than independent development.
  • Post-exploitation reached victims via the SUPERSTOMP loader, which installed the LONGTALE credential-stealing Chrome extension masquerading as Google Gemini.
  • Campaign observed from 1 September 2026 against US defence contractors, NGOs, mining/commodity firms and Southeast Asian government agencies.

TTPs

  • Browser zero-day chaining against Chrome (V8 โ†’ WebAssembly โ†’ Windows kernel) for full remote compromise.
  • Patch-gap weaponisation: the underlying Chromium fix shipped upstream before reaching Chrome users โ€” a window the actors exploited within days.
  • Credential-stealing browser extension as the post-exploitation payload, blending espionage collection with persistence.

Significance

JungleBamboo's use of a byte-identical exploit kit shared with other China-linked groups is the key evidence for a commercialised or brokered Chinese exploit supply chain โ€” the rare public convergence of multiple espionage actors on a common offensive tool. See Patch Gap Zero Day Weaponisation for the broader tradecraft.

Related Pages