Once in a BlueMoon: Inside the Exploit Chain Four Espionage Groups Adopted in Days
Show notes
Hello to all our cybernauts!
This week Selena is joined by not one, not two, but three guests — Mark Kelly, Julia Paluch, and Dave Galazin — to unpack Proofpoint's latest research. Mark walks through how it started: on August 28, the China-aligned actor TA412 (aka Violet Typhoon), previously known mostly for device registration phishing, suddenly began delivering a Chrome exploit — kicking off a frantic cross-team investigation involving partners at Google and Microsoft. Within days, three more state-sponsored clusters adopted the same exploit chain, dubbed BlueMoon; by the time the blog published, that number had grown to seven distinct clusters, plus an eCrime actor and a brand-new espionage group picking it up since.
Julia breaks down the Chrome half of the chain — a type confusion bug in the V8 engine chained with a sandbox escape — and introduces the concept of the "patch gap": the roughly four-week window between when a fix is committed to the public Chromium codebase and when it's fully rolled out to stable Chrome releases. During that window, the regression test accompanying the fix effectively doubles as a roadmap for building an exploit, especially with an LLM doing the heavy lifting of interpreting it.
Dave then covers the Windows half: a kernel heap bug that lets an attacker escalate from Chrome's heavily sandboxed, untrusted-integrity renderer process straight to full privileges — without needing any file system access first. He and Mark also make the case that this particular Windows exploit had likely been sitting unused for over a year, based on consistent compilation timestamps across the payload's debug information.
Selena, Mark, Julia, and Dave also dig into:
- Why the deployment looked rushed: exploit kits full of debug logging and comments, a downloader left behind indefinitely, and a Windows exploit that doesn't even check what OS the victim is running
- Historical precedent for this kind of rapid multi-actor tool sharing among Chinese threat actors, including 2021's ProxyLogon and 2025's ToolShell activity
- Evidence pointing toward AI-assisted exploit development — including leftover debugging comments and variable names lifted straight from the public regression test
- Whether the open-source community's transparency (public commits, public regression tests) needs to change in light of this kind of patch-gap weaponization
- Why Windows zero-days are much rarer to find "on the shelf" than browser bugs, and what that implies about how this one got used
- Practical defensive takeaways: post-exploitation detection still matters most, since noisy, AI-assisted tradecraft is easier to catch than the initial exploit itself
Plus: a very enthusiastic Chrome-tab-hoarding discussion, Julia's advice to enable Chrome crash reporting, and a well-earned round of "you need a vacation, Mark."
Resources Mentioned:
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
For more information about Proofpoint, check out our website.