How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
The BlueMoon Exploit Kit is an advanced malware delivery framework that chains two V8 JavaScript engine vulnerabilities with a Windows kernel exploit to escape browser sandboxes. It enables deployment of multiple payloads, including GemStone, ShadowPad, and custom Rust-based loaders, through spearphishing campaigns. The exploit kit is being used by several espionage-focused threat clusters targeting organizations across the US and Southeast Asia.
Investigation
The analysis outlines the complete exploitation chain, beginning with V8 type confusion (CVE-2026-85046) and sandbox escape (CVE-2026-87491), followed by kernel privilege escalation through CVE-2026-85880. Researchers traced how execution progresses from the renderer process into the browser’s parent broker process to run arbitrary commands. The investigation also documented payload behavior, including GemStone browser extension persistence and ShadowPad data theft functionality.
Mitigation
Defenders should prioritize patching Chrome and Windows to remediate the identified CVEs, particularly because the kernel exploit targets older Windows builds. Security teams should monitor suspicious browser extension installations and unexpected executable downloads, such as msgbox.exe appearing in the %TEMP% directory. Organizations should also strengthen email filtering against spearphishing links and monitor for unauthorized scheduled tasks such as EdgeCore_AutoUpdate.
Response
When BlueMoon activity is detected, incident responders should isolate the affected host to prevent additional payload execution and lateral movement. Perform forensic analysis of the %TEMP% directory and browser profiles to identify dropped files and malicious extensions. Review network logs for connections to known C2 infrastructure and investigate unauthorized persistence mechanisms, including newly created registry keys or scheduled tasks.
Attack Flow
We are still updating this part.
Detections
Suspicious CURL Usage (via cmdline)
Suspicious Files in Public User Profile (via file_event)
Detection of BlueMoon Exploit Kit Activity via Privilege Escalation and Code Injection [Windows Process Creation]
BlueMoon Exploit Kit Malware Execution via Spearphishing [Webserver]
Simulation Execution
-
Attack Narrative & Commands: The adversary aims to exploit a browser vulnerability to gain elevated privileges. In a real-world scenario, this happens in memory; however, to validate this specific detection rule, we will simulate the artifacts the rule is looking for. The attacker executes a command-line instruction that mimics the behavior described in the BlueMoon research, including the strings “raises the renderer’s privileges” and “Base64” to trigger the logic.
-
Regression Test Script:
# Simulation script to trigger the BlueMoon detection rule # This script mimics the command line strings the rule is searching for. $ExploitCommand = "cmd.exe /c echo 'Executing payload: Base64 JavaScript exploit code' && echo 'This process raises the renderer's privileges and injects code into the browser's parent broker process'" Write-Host "[!] Starting Simulation: Executing command to trigger detection..." Start-Process cmd.exe -ArgumentList "/c $ExploitCommand" -Wait Write-Host "[+] Simulation Complete." -
Cleanup Commands:
# No permanent artifacts are created by the simulation script. # Simply verifying no rogue processes are running. Get-Process | Where-Object {$_.CommandLine -like "*BlueMoon*"} | Stop-Process -Force -ErrorAction SilentlyContinue