Volexity and Proofpoint independently documented at least four-to-six China-linked espionage groups โ including JungleBamboo (APT31/Violet Typhoon) and the MSS-aligned UTA0560 โ using the identical browser exploit kit dubbed "BlueMoon" against US defence contractors, NGOs, mining/commodity firms and Southeast Asian government agencies, beginning late August 2026. The chain couples a Chrome V8 type-confusion zero-day (CVE-2026-85046), a WebAssembly sandbox-escape flaw (CVE-2026-87491) and a Windows kernel vulnerability (CVE-2026-85880), with byte-for-byte identical exploit code and shellcode suggesting a shared supply chain or exploit broker. Post-exploitation payloads included the GRIMWEDGE JScript backdoor (UTA0560) and, via JungleBamboo, the SUPERSTOMP loader installing the LONGTALE credential-stealing Chrome extension masquerading as Google Gemini.
| Attribute | Detail |
|---|---|
| Date | Starting 1 September 2026 (phishing observed) |
| Type | Zero-day browser exploit chain / targeted espionage |
| Actors | JungleBamboo (APT31/Violet Typhoon), UTA0560 + others (China-linked) |
| CVEs | CVE-2026-85046, CVE-2026-87491, CVE-2026-85880 |
| Source | Volexity / Proofpoint โ Tier 1/4 |
The exploited Chrome vulnerability had been fixed in the open-source Chromium codebase but not yet reached Chrome users, creating an unusual "patch gap" the actors weaponised within days. Google subsequently moved Chrome to a two-week release cycle.