BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days
BlueMoon exploit kit bundles Chrome renderer and Windows privilege-escalation zero-days into a two-stage chain, with espionage-motivated actors adopting it in rushed campaigns.

An exploit kit called BlueMoon is being used by multiple threat actors to chain recently patched Chrome and Windows zero-days against targets, SecurityWeek reported on September 12. The campaigns are espionage-motivated, and the deployments are described as opportunistic and rushed rather than long-planned operations.
How the chain works
Exploit kits work by hosting bundled exploits on an attacker-controlled server. A target browser loads the kit’s landing page, the server checks the software version, and the appropriate exploit fires. BlueMoon uses a two-stage structure: a browser-side flaw for initial code execution, followed by a Windows privilege escalation bug to break out of the browser sandbox and reach the operating system. That sequence converts a browser compromise into full OS access without requiring any further action from the target.
The Chrome-side components align with the series Google has patched through mid-2026. Google closed Chrome’s seventh exploited zero-day of the year on September 9. For Windows, Microsoft’s September Patch Tuesday addressed two actively exploited vulnerabilities the same day, and the Nightmare Eclipse campaign separately disclosed a Windows Defender zero-day on September 11. SecurityWeek’s report does not identify which specific CVE identifiers BlueMoon bundles.
Espionage framing, rushed timelines
SecurityWeek characterizes the actors using BlueMoon as espionage-motivated, which separates these campaigns from the mass-infection spray typical of commodity ransomware kits. Espionage-oriented operators tend to target fewer, higher-value systems rather than broad infection sweeps. The “rushed” deployment pattern is consistent with threat groups moving quickly to exploit zero-days before the patch window closes, using whatever kit is available rather than one built specifically for the target environment.
SecurityWeek did not attribute the campaigns to a named threat actor or country.
What to do
Install the latest Chrome update and apply Microsoft’s September 2026 cumulative patches. For systems that cannot patch immediately, restricting browser-process network access and blocking traffic to known drive-by infrastructure limits the delivery vectors BlueMoon uses to reach targets.
Found this useful? Share it.


