SecPod

Learn Search

Search across all Learn content

← Back to Security Research

September 2026 - Threat Actor Activity Report: TA412 Chains Chrome and Windows Zero-Days for Browser Espionage

Sep 29, 2026By Rinu K

1. Executive Summary

TA412 is a China-aligned espionage actor whose late-August and early-September 2026 campaigns used the BlueMoon exploit kit. Proofpoint first observed its use on 28 August; September reporting connected the activity to US nongovernmental organizations, mining companies, and physical commodity traders.

CVEs in the observed chain: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. Together, they connect browser memory corruption, a V8 sandbox escape, and Windows privilege escalation. Vendor fixes are available for all three; their historical zero-day status should not be confused with being unpatched today.

  • Priority 1 - Close the exploitation path. Deploy current supported browser releases and applicable Windows security updates. Verify installed versions after the required browser restart or operating-system reboot; do not treat an update merely downloaded or scheduled as deployed. The versions in Section 4 are minimum fixed thresholds, not recommended current deployment targets. [11][12][14]
  • Priority 2 - Investigate persistence independently of patching. Examine extension installations and browser-profile changes on potentially exposed hosts. A closed vulnerability and an authorized extension inventory are separate checks; satisfying one does not establish the other. [21]
  • Priority 3 - Contain identity exposure. Where browser compromise is established, investigate affected accounts and revoke exposed sessions from a trusted device. Password changes alone should not be treated as proof that stolen session material is unusable. [22]

2. Actor Profile

Source / tracking system Name or identifier
Proofpoint TA412
Volexity JungleBamboo
Microsoft Violet Typhoon; formerly ZIRCONIUM
Mandiant / Google APT31
CrowdStrike JUDGMENT PANDA
MITRE ATT&CK G0128 - ZIRCONIUM; associated names APT31 and Violet Typhoon

These names provide cross-vendor context, not a guarantee that every vendor defines precisely the same operational boundary. Campaign attribution below remains attached to the reporting vendor; shared malware or CVEs alone are not treated as proof of common operators.

Suspected origin and sponsorship: China. In its March 2024 indictment announcement, the US Department of Justice alleged that APT31 operated within an espionage program run by the Ministry of State Security's Hubei State Security Department. This is an official attribution allegation, not a finding that every publicly reported intrusion has been judicially proven.

Motivation and baseline targeting: Mandiant describes APT31 as pursuing information with political, economic, and military value. Its historical sector coverage includes government, finance, aerospace and defense, technology, telecommunications, and media. These are baseline targets, not a list of September victims.

Toolset and operating baseline

The current campaign combines BlueMoon, a loader Volexity calls SUPERSTOMP, and a malicious browser extension called LONGTALE by Volexity and GemStone by Proofpoint. The extension impersonates Google Gemini. Its installation uses browser-profile tampering rather than a normal user-approved store installation. The legitimate tools cmd.exe and curl are also abused for payload retrieval and launch.

Historically, Proofpoint documented TA412 using tracking pixels against journalists: email engagement revealed information useful for further targeting. Such reconnaissance is relevant to its people-focused tradecraft, but it is not itself CVE exploitation. Mandiant also lists SOGU, LUCKYBIRD, SLOWGYRO, and DUCKFAT in the broader historical APT31 toolset; their inclusion here does not indicate deployment this month.

Selected historical CVE exploitation record

Period / evidence CVE and vulnerability class What the record supports
2014-2015 code artifacts; research published in 2021 CVE-2017-0005 - Windows local privilege escalation Check Point linked the Jian exploit to APT31 and reconstructed its reuse of Equation Group exploit technology. The flaw was patched on 14 March 2017. Artifact dates are not an exact first-observed attack date.
July 2025 CVE-2025-49706 - spoofing / authentication bypass; CVE-2025-49704 - SharePoint RCE Microsoft named Violet Typhoon among actors exploiting on-premises SharePoint. Its earliest July observations cover the wider campaign, not necessarily a separately established first date for this actor.
August-September 2026 CVE-2026-85046 + CVE-2026-87491 + CVE-2026-85880 Current browser-to-Windows chain; detailed in Section 4.

The SharePoint report also discusses related bypass fixes, CVE-2025-53770 and CVE-2025-53771. They are not counted here as two additional, independently demonstrated TA412 exploitation events. Similarly, ransomware activity attributed to Storm-2603 in that report is not transferred to Violet Typhoon.

3. Activity Summary for the Period

Date Event How to interpret it
7 August 2026 Upstream fix for CVE-2026-85046 committed. Pre-period context: source-code remediation preceded stable-browser availability.
28 August 2026 Proofpoint first observed TA412 using BlueMoon. Carry-in campaign baseline; not the first possible exploitation worldwide.
1-2 September 2026 Volexity observed JungleBamboo phishing; the 2 September link served the exploit chain. The 1 September URL was unavailable during analysis; do not claim it independently yielded a recovered exploit.
3 September 2026 Chrome 152 update fixed CVE-2026-85046. Stable-release patch date.
4 September 2026 CVE-2026-85046 added to CISA KEV. Public confirmation of known exploitation, not an actor-specific attribution record.
8 September 2026 Chrome 153 fixed CVE-2026-87491; Microsoft released the ALPC fix; CVE-2026-85880 entered KEV. Both vendor update streams matter to the chain.
9 September 2026 Proofpoint and Volexity published analyses; CVE-2026-87491 entered KEV. Disclosure date is distinct from exploitation date.

Campaign separation: Other BlueMoon users were tracked as UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket, and UTA0560. Their operations are not automatically TA412 campaigns. In particular, UTA0560's GRIMWEDGE payload and reflected-XSS delivery route are excluded from TA412's chain.

The reporting cutoff is 29 September 2026. The cited campaign observations concern late August and early September; they do not establish uninterrupted activity or new successful compromises throughout the rest of the month.

4. CVE Exploitation Analysis

CVE inventory

CVE ID Vendor, product, affected versions CWE / class CVSS base EPSS: 28 Sep CISA KEV / added Status when first observed Patch release First TA412 chain observation
CVE-2026-85046 Google Chrome / V8 Before 152.0.7977.82 CWE-843 Type confusion 8.8 Vector A CISA ADP 0.48881 48.881% Yes 4 Sep 2026 Patch-gap zero-day 3 Sep 2026 28 Aug 2026
CVE-2026-87491 Google Chrome / V8 Before 153.0.8010.36 CWE-787 Out-of-bounds write 8.8 Vector A CISA ADP 0.03142 3.142% Yes 9 Sep 2026 Patch-gap zero-day 8 Sep 2026 28 Aug 2026
CVE-2026-85880 Microsoft Windows / ALPC Affected branches listed below CWE-122 and CWE-908 Heap overflow / uninitialized resource 7.8 Vector B Microsoft CNA 0.03616 3.616% Yes 8 Sep 2026 Zero-day 8 Sep 2026 28 Aug 2026

Vector A: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector B: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The browser scores are CISA ADP assessments, not independent NVD scores or Google's product-severity labels. Google classifies CVE-2026-87491 as Medium in its own severity scheme; that is separate from the 8.8 CVSS assessment.

Windows affected branches and minimum fixed builds

Product / release branch Affected builds are below this fixed build
Windows 10 1607; Windows Server 2016 10.0.14393.9512
Windows 10 1809; Windows Server 2019 10.0.17763.9245
Windows 10 21H2 10.0.19044.7725
Windows 10 22H2 10.0.19045.7725
Windows Server 2012 6.2.9200.26349
Windows Server 2012 R2 6.3.9600.23398
Windows Server 2022 10.0.20348.5622

Source: Microsoft CNA record updated 25 September 2026. Comparisons apply within each release branch, not across unrelated builds. Consult the advisory for architecture, edition, servicing eligibility, and Server Core details.

Scoring, version, and measurement caveats

EPSS snapshot: The table uses values dated 28 September 2026, preserved in CIRCL Vulnerability-Lookup's timestamped EPSS fields; these are not asserted to be September 29 values. FIRST's direct API could not be independently retrieved. EPSS estimates exploitation probability over the next 30 days, not whether exploitation has already occurred. Confirmed exploitation takes precedence over a low predictive score.

Product scope versus exploit scope: Vendor advisories define affected products. An exploit's operating-system checks define where that particular implementation attempts to run. These are different datasets; an observed build-selection check should neither expand nor shrink the vendor's affected-product list. In this case, BlueMoon's Windows stage was constrained to selected older builds.

Pattern analysis: what the CVEs reveal

Complementary vulnerabilities, rather than three interchangeable entry points. Two flaws affect browser memory handling; the third provides local operating-system privilege escalation. The useful unit of analysis is the ordered chain. A high browser score does not mean it alone performs every later action, and a local Windows flaw is not equivalent to an unauthenticated network RCE.

Patch-gap timing is the distinguishing feature. For CVE-2026-85046, the 7 August upstream fix preceded the 3 September stable release by 27 days. TA412's first reported use fell 21 days after that source fix and six days before the stable update. These intervals are calculated from the reported dates; they do not prove when the actor obtained or developed the exploit.

Time-to-exploit requires a signed interval. Relative to public patch release, the first reported chain use was 6 days before the fix for CVE-2026-85046 and 11 days before fixes for CVE-2026-87491 and CVE-2026-85880. Calling these post-patch exploitation delays would reverse their meaning.

Zero-day versus n-day depends on the boundary. Under an end-user patch-availability definition, the chain began as 3 zero-days to 0 patched n-days. Two were already repaired upstream, making them source-level n-days but stable-release patch-gap zero-days. After vendor fixes became available, exploitation of still-vulnerable installations is n-day exploitation. This ratio describes this three-CVE chain, not TA412's lifetime activity. Google's patch-gap guidance uses the source-level n-day terminology.

Product affinity should not be overstated. The current sample is two Chrome/V8 flaws and one Windows flaw, spanning type confusion, an out-of-bounds write, and a heap-overflow issue. Historically documented SharePoint exploitation shows another entry surface. The defensible conclusion is adaptability across an enterprise software stack, not a statistically established preference for one vendor.

Reuse is better supported than authorship. Jian research documents earlier reuse of another actor's exploit technology. That makes acquisition and adaptation useful hypotheses to track, but it does not prove TA412 authored, purchased, or exclusively controlled BlueMoon. Attribution should retain separate fields for exploit developer, distributor, and observed operator.

CVE-2026-85046: the initial memory-corruption primitive

The researcher's analysis describes inconsistent assumptions around optimized Array.prototype.sort handling and array element types. Side effects involving Array.fill can leave stored objects interpreted with the wrong type. The resulting type confusion enables arbitrary reads and writes in the JavaScript heap. Both Maglev and TurboFan are implicated, although the public walkthrough focuses on Maglev. The upstream change requires compatible element kinds before this optimization is applied.

This is a foothold inside V8's memory region, not by itself unrestricted operating-system execution. The public researcher write-up demonstrates the vulnerability, while the campaign reporting establishes weaponized use. A public demonstration of one component should not be represented as a verified public release of the complete BlueMoon kit.

Fix and impact: Chrome versions before 152.0.7977.82 are affected. The September 3 update closes this component; deploy a current supported release rather than stopping at that historical minimum. The network attack vector and required user interaction describe malicious content reaching a browser, not a remotely exposed server service.

CVE-2026-87491: crossing the V8 sandbox

Google identifies an out-of-bounds write in V8, affecting Chrome before 153.0.8010.36. In the chain, corrupted WebAssembly-related metadata helps turn the initial memory primitive into native code execution outside the V8 sandbox. The public CVE description is deliberately less detailed than the campaign analysis.

The two sandboxes must remain distinct. V8's sandbox constrains engine-memory corruption within a renderer process. Chrome's renderer sandbox is an operating-system isolation boundary around that process. Escaping the former does not inherently defeat the latter; another stage is still needed to cross into a less restricted process.

Fix and exploit availability: Chrome 153.0.8010.36, released September 8, provides the minimum fixed threshold. In-the-wild weaponization is established, but this report does not verify a separately downloadable, public standalone exploit. The CVE record was published September 9; that UTC publication timestamp is not a reason to move the September 8 release date.

CVE-2026-85880: local privilege escalation completing the chain

Microsoft describes a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), with CWE-122 and CWE-908 recorded. It requires local access and allows privilege escalation. The browser stages provide the execution context from which the Windows stage can be attempted; the ALPC flaw is not an independent internet-facing entry point.

The reported implementation elevates execution and injects into the browser broker process, enabling the payload-launch step outside the restricted renderer. Do not translate that result into a blanket claim that every affected Windows edition, every browser build, or every attempt achieved SYSTEM-level compromise.

Fix and response: Microsoft released updates September 8, and the current CNA record supplies the branch-specific fixed builds above. Installation of that update addresses the vulnerability; investigation of a suspected intrusion must still establish whether persistence or account exposure occurred before remediation. Weaponized exploitation is confirmed; a public standalone exploit was not independently verified here.

Post-exploitation and exposure

The loader installs the extension through Secure Preferences tampering. LONGTALE can capture keystrokes, cookies, browser storage, and screenshots; it supports remote collection commands. Those are analyzed malware capabilities, not proof that every feature ran against every target.

External exposure count: Not measured. No Shodan or Censys query was run as of 29 September 2026. This is a user-browser exploitation path; counting publicly reachable servers would not establish how many endpoints have the required browser-and-Windows combination. An external count of zero would therefore be especially misleading.

For an internal assessment, join endpoint identity, installed browser version, running browser version, Windows release/build, patch state, and user-risk context. Count unique devices, retain the observation timestamp, and distinguish vulnerable software from evidence of exploitation. This is a recommended measurement approach, not a measured result.

5. TTP Mapping

The following ATT&CK mappings are analyst-assigned interpretations of the cited behavior. CVEs describe the exploit stages; later techniques are enabled by the resulting access and are not additional exploits. Collection rows describe demonstrated capabilities unless victim-specific use is established.

Tactic Technique / sub-technique Behavior or capability Linked CVE / stage Evidence
Initial Access - Spearphishing Link Phishing link initiates delivery. Delivery before exploitation
Execution - Exploitation for Client Execution Browser exploit stages. 85046 and 87491
Privilege Escalation - Exploitation for Privilege Escalation Windows ALPC escalation. 85880
Stealth - Process Injection Execution in the browser broker. After 85880; no extra CVE
Persistence - Browser Extensions Malicious extension installation. Post-exploitation
Credential Access - Steal Web Session Cookie Cookie collection capability. Post-exploitation
Collection / Credential Access - Keylogging Keystroke capture capability. Post-exploitation
Collection - Screen Capture Screenshot capability. Post-exploitation
Command and Control - Web Service: Bidirectional Communication Cloudflare Workers-based C2. Post-exploitation

CVE shorthand in the table expands to CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The current ATT&CK page lists Stealth for ; the browser-extension sub-technique is .

Attack path

Phishing link -> CVE-2026-85046 -> CVE-2026-87491 -> CVE-2026-85880 -> broker-process execution -> malicious extension -> browser surveillance and collection.

Lateral movement: Not established for TA412 in the cited September campaign reporting. Its absence from this reconstruction is an evidence limit, not proof that the actor lacks the capability. No ransomware stage is inferred.

New versus recurring behavior

The recurring pattern is targeting people through email and seeking access to browser-held information. Proofpoint's earlier beaconing research and MITRE's historical credential-access entries support that baseline. What distinguishes this reporting period is the documented multi-CVE route to browser-based persistence, rather than a demonstrated first-ever use of phishing or credential theft by the actor.

Selected campaign artifacts

Artifact type Reported indicator Use in investigation
Phishing destinations photos.msbenefit[.]com; proof.gitprogram[.]com Correlate historical mail, proxy, and endpoint records.
Extension identifier ckiknalbeplpcpofpnabcnhjcegckfei Compare against installed and historically removed extensions.
Extension staging path C:\Users\Public\stomp_ext A filesystem lead, not a standalone verdict.

Domains are defanged. Validate indicator age, ownership, and local context; do not block shared infrastructure solely by provider name.

Detection and mitigation priorities

Correlate the sequence, not a single process name. Proposed hunting logic should connect suspicious browser activity, abnormal process access, payload execution, and unexpected extension or profile changes on the same endpoint. Browser crashes or profile writes alone are not conclusive; process-injection telemetry and unauthorized extension state provide stronger context. This is a detection hypothesis, not a validated rule.

Review extensions and identity together. Use managed extension allowlists and compare installed extensions against approved inventory. Investigate unexplained permissions or installation changes. Where session theft is suspected, correlate account access with endpoint findings and invalidate exposed sessions; do not assume multifactor authentication retroactively protects already-stolen session cookies.

Treat shared cloud infrastructure carefully. Inspect application context, hostname, and endpoint behavior before blocking. ATT&CK documents how adversaries can use legitimate web services for command and control; ordinary traffic to a shared provider is not sufficient evidence of compromise.

7. Targeting and Victimology

The September campaign's reported US NGO, mining, and commodity-trading focus should be read against a broader historical intelligence-collection baseline, not merged with every sector targeted by other BlueMoon users. Public targeting reports also should not be converted into a count of successfully compromised organizations.

Analyst assessment: These targets plausibly hold policy discussions, commercial negotiations, supply-chain information, and communications of intelligence value. That is a reason to prioritize relevant users for investigation, not a claim that specific documents or transactions were stolen. The exposure model is the person's browsing environment and authenticated access, rather than a sector-specific vulnerable server product.

A useful tracking record should therefore keep four dimensions separate: actor-attributed campaign, ordered CVE chain, post-exploitation behavior, and victim evidence. Record whether each entry is observed, inferred, or unverified. A shared exploit should not silently merge actors, and a vulnerable endpoint should not silently become a confirmed victim. Patch closure is not incident closure.

Featured Posts

Open Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited
Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

CVE Research

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.

Sep 28, 2026

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026