Since September 1, two Chinese hacking groups separately exploited the same previously unknown flaws in Microsoft Windows and Google Chrome within the short period this month, deploying different malware against non-governmental organizations and other targets using a newly discovered Google Chrome Zero Day vulnerability, according to security firm, Veloxity.
According to Veloxity, one group, which it tracks as UTA0560, targeted multiple Non-Governmental Organizations (NGO) on September 1, through spear-phishing emails directing recipients to a legitimate university website compromised with a cross-site scripting flaw.
BlueMoon Exploits Browser Patch Gap
Hackers quickly turned newly disclosed security fixes into working tools. Researchers found several separate groups using BlueMoon, questioning whether the exploit kit was shared, sold, or supplied by the same developer to different operators.
Victims who clicked the link and were using Chrome on Windows were redirected to attacker-controlled infrastructure hosting an exploit chain combining three separate vulnerabilities.
The campaign eventually exploited a Chrome zero day to begin compromising vulnerable systems
“The emails contained a message encouraging the users to click a link that led to the website of a U.S.-based university,” said Volexity researchers.
“These links abused a reflected cross-site scripting (XSS) vulnerability on the website, redirecting recipients to threat-actor-controlled infrastructure hosting a multi-stage exploit chain,” the researchers added.
The technical problem started with the timing of a Chromium patch. Security fixes had already appeared in Chromium’s public source code, but they had not yet reached users running the stable version of Chrome.
That gave attackers an opportunity to study what had changed and potentially understand the underlying vulnerability.
BlueMoon chained three flaws. CVE-2026-85046 allowed attackers to gain memory access inside Chrome’s V8 sandbox, CVE-2026-87491 then helped escape the browser sandbox, while CVE-2026-85880 exploited Windows ALPC to raise privileges.
Together, they transformed Google Chrome zero day from a browser’s weakness into a path toward wider system access.
That process shows why a Chromium based browser patch can become sensitive before users actually receive an update. Public code changes can reveal clues about the flaw, while millions of devices may remain exposed until the stable browser release reaches them.
After gaining access, UTA0560 deployed GRIMWEDGE, a JavaScript backdoor capable of system reconnaissance, file management, process monitoring, command execution and downloading further payloads. Researchers revealed the malware gave attackers enough control to inspect compromised computers and decide what to steal or deploy next.
“The code has no built-in persistence, lateral movement, or exfiltration mechanism beyond the file-read and upload commands,” according to Volexity.
Researchers added that the backdoor still provided enough access to examine the victim’s system, retrieve files, and install additional tools.
One Exploit Kit Reaches Several Chinese-Linked Groups
A second China-linked group involved in a separate Chrome zero day campaign, was tracked as JungleBamboo – known as APT31.
The group used the identical exploit chain around the same time to install a credential-stealing Chrome extension disguised as a legitimate Google Gemini extension, according to Veloxity.
The tool, referred to by the research firm as LONGTALE or GemStone, was designed to log keystrokes, steal cookies and session data, capture screenshots, and periodically exfiltrate stolen information.
It’s with noting that Veloxity highlighted it lacked any built-in mechanism for further remote code execution, suggesting its authors judged the surveillance capability alone sufficient for the group’s objectives.
Researchers also saw the same exploit chain targeting US aerospace and defense companies, a Vietnamese manufacturer, and organizations in Southeast Asia.
The repeated use of BlueMoon suggests that the Google Chrome zero day chain may have been distributed as a shared modular capability rather than developed independently by every group.
The main security problem is Chromium patch-gap Window. Even after developers fix a vulnerability upstream, attackers still have time to reverse-engineer that security change before the official browser update reaches ordinary users.
A second Chromium patch concern becomes important when exploit developers monitor public source-code changes. Volexity warned that patch gaps can give threat actors an additional period in which a known technical weakness remains usable against downstream software.
Google has since shortened Chrome’s major release cycle, reducing the amount of time between some security changes and stable releases. Faster delivery of a Chromium based browser patch could make it harder for attackers to study a fix and weaponize it before users receive protection.
The case also demonstrates why Chromium patches themselves are increasingly valuable for intelligence for attackers. Security researchers warn that AI tools could make it faster to examine code changes, locate the repaired weakness, and assist with developing a working exploit.
For defenders, the Google Chrome zero day campaign shows that patching speed now matters beyond simply installing updates once they arrive. Browser makers must also reduce the time between developing a fix and safely placing it on users’ machines.
Therefore, reports that Google issues emergency Chrome update for exploited zero day vulnerability highly reflect the race between software vendors and attackers. Also, BlueMoon shows that even when a vulnerability has technically been fixed, the delay before that protection reaches users can become an attack opportunity.
Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Intelligent Tech sections to stay informed and up-to-date with our daily articles.
