DISCARDED: Tales From the Threat Research Trenches
DISCARDED: Tales From the Threat Research Trenches

Once in a BlueMoon: Inside the Exploit Chain Four Espionage Groups Adopted in Days

Show notes

Send us fan mail!

Hello to all our cybernauts!

This week Selena is joined by not one, not two, but three guests — Mark Kelly, Julia Paluch, and Dave Galazin — to unpack Proofpoint's latest research. Mark walks through how it started: on August 28, the China-aligned actor TA412 (aka Violet Typhoon), previously known mostly for device registration phishing, suddenly began delivering a Chrome exploit — kicking off a frantic cross-team investigation involving partners at Google and Microsoft. Within days, three more state-sponsored clusters adopted the same exploit chain, dubbed BlueMoon; by the time the blog published, that number had grown to seven distinct clusters, plus an eCrime actor and a brand-new espionage group picking it up since.

Julia breaks down the Chrome half of the chain — a type confusion bug in the V8 engine chained with a sandbox escape — and introduces the concept of the "patch gap": the roughly four-week window between when a fix is committed to the public Chromium codebase and when it's fully rolled out to stable Chrome releases. During that window, the regression test accompanying the fix effectively doubles as a roadmap for building an exploit, especially with an LLM doing the heavy lifting of interpreting it.

Dave then covers the Windows half: a kernel heap bug that lets an attacker escalate from Chrome's heavily sandboxed, untrusted-integrity renderer process straight to full privileges — without needing any file system access first. He and Mark also make the case that this particular Windows exploit had likely been sitting unused for over a year, based on consistent compilation timestamps across the payload's debug information.

Selena, Mark, Julia, and Dave also dig into:

  • Why the deployment looked rushed: exploit kits full of debug logging and comments, a downloader left behind indefinitely, and a Windows exploit that doesn't even check what OS the victim is running
  • Historical precedent for this kind of rapid multi-actor tool sharing among Chinese threat actors, including 2021's ProxyLogon and 2025's ToolShell activity
  • Evidence pointing toward AI-assisted exploit development — including leftover debugging comments and variable names lifted straight from the public regression test
  • Whether the open-source community's transparency (public commits, public regression tests) needs to change in light of this kind of patch-gap weaponization
  • Why Windows zero-days are much rarer to find "on the shelf" than browser bugs, and what that implies about how this one got used
  • Practical defensive takeaways: post-exploitation detection still matters most, since noisy, AI-assisted tradecraft is easier to catch than the initial exploit itself

Plus: a very enthusiastic Chrome-tab-hoarding discussion, Julia's advice to enable Chrome crash reporting, and a well-earned round of "you need a vacation, Mark."

Resources Mentioned:

Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880


For more information about Proofpoint, check out our website.