Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, china, chrome, zero-day, espionage, patch-gap, state-sponsored] ยท confidence: high ยท affected_sectors: [defence, government, technology] ยท au_impact: true

Volexity and Proofpoint independently documented at least four-to-six China-linked espionage groups โ€” including JungleBamboo (APT31/Violet Typhoon) and the MSS-aligned UTA0560 โ€” using the identical browser exploit kit dubbed "BlueMoon" against US defence contractors, NGOs, mining/commodity firms and Southeast Asian government agencies, beginning late August 2026. The chain couples a Chrome V8 type-confusion zero-day (CVE-2026-85046), a WebAssembly sandbox-escape flaw (CVE-2026-87491) and a Windows kernel vulnerability (CVE-2026-85880), with byte-for-byte identical exploit code and shellcode suggesting a shared supply chain or exploit broker. Post-exploitation payloads included the GRIMWEDGE JScript backdoor (UTA0560) and, via JungleBamboo, the SUPERSTOMP loader installing the LONGTALE credential-stealing Chrome extension masquerading as Google Gemini.

Attribute Detail
Date Starting 1 September 2026 (phishing observed)
Type Zero-day browser exploit chain / targeted espionage
Actors JungleBamboo (APT31/Violet Typhoon), UTA0560 + others (China-linked)
CVEs CVE-2026-85046, CVE-2026-87491, CVE-2026-85880
Source Volexity / Proofpoint โ€” Tier 1/4

The exploited Chrome vulnerability had been fixed in the open-source Chromium codebase but not yet reached Chrome users, creating an unusual "patch gap" the actors weaponised within days. Google subsequently moved Chrome to a two-week release cycle.

Source