BlueMoon Phishing Uses Browser Zero-Days to Spy

The Register Security · High sophistication
Last updated September 10, 2026

Multiple suspected China-linked espionage groups used a new exploit kit (“BlueMoon”) that starts with phishing emails and a malicious link to break into organizations in the US and Southeast Asia. Clicking the link can trigger browser and Windows vulnerabilities to install surveillance tools, including a fake “Google Gemini” browser extension that steals data and takes screenshots. Different campaigns tailored lures to specific industries, including internship inquiries, defense RFQs, and Indonesian conference invitations.

How the Attack Worked

BlueMoon is a shared exploit kit that at least four suspected espionage groups used against organizations in the US and Southeast Asia. Every campaign began the same way: a phishing email convinced the recipient to click an attacker-controlled link. From there, the link could trigger two Chromium V8 vulnerabilities combined with a Windows privilege escalation bug (CVE-2026-85880), letting attackers run code and install surveillance payloads with minimal additional interaction from the victim.

One campaign went further, installing a browser extension disguised as Google Gemini. That fake extension stole cookies and other sensitive browser data, captured screenshots, and injected a keylogger into browser tabs, giving attackers ongoing visibility into victim activity long after the initial click.

Why It Succeeded

Each group tailored its pretext to the audience it wanted to reach. One campaign impersonated a university student seeking an internship and asked HR or recruiting staff to click a link to view application details. Another used request-for-quotation lures aimed at procurement and sales staff at US aerospace companies, hosting the fake RFQ on domains spoofing real aerospace firms. A third used invitations to real-sounding Indonesian conferences and forums to draw in executives, consultants, and government relations staff.

These lures worked because they mirrored ordinary business communication: recruiting emails, vendor RFQs, and event invitations are routine, so a single link click did not feel unusual. The technical exploit chain then did the rest of the work silently.

What to Watch For

  • Unsolicited emails asking you to click a link for internship applications, RFQs, or conference registrations, especially from unfamiliar senders
  • Links that route to domains that do not match the organization named in the email, such as spoofed aerospace company domains
  • New or unexpected browser extensions appearing after clicking a link, particularly ones claiming to be well-known tools like Google Gemini
  • Urgency or pressure to click through a link instead of using a normal channel like a resume attachment or established vendor portal

Building Resistance

Organizations across HR, procurement, sales, and executive support functions should treat unsolicited link-based requests as high risk and verify them through a separate, trusted channel before clicking. IT and security teams should prioritize rapid patching of browsers and Windows, since attackers can weaponize publicly visible open-source fixes during the gap before stable releases are broadly deployed. Employees should also be trained to notice unfamiliar browser extensions and report them immediately, since a fake extension was used in at least one campaign to quietly harvest data, screenshots, and keystrokes after the initial phishing click succeeded.

Key findings

  • At least four espionage groups used a shared exploit kit (“BlueMoon”) that begins with phishing emails containing attacker-controlled links.
  • The attack chain used two Chromium V8 issues plus a Windows privilege escalation bug (CVE-2026-85880) to run code and install payloads.
  • One campaign installed a malicious browser extension disguised as “Google Gemini” to steal cookies/data, take screenshots, and keylog within the browser.
  • Other campaigns used tailored lures: internship outreach, defense-industry requests for quotation, and Indonesian conference invitations.
  • The article highlights rapid exploit development during “patch-gap” windows, where upstream open-source fixes are visible before stable releases are widely patched.

Who’s being targeted

  • Commonly targeted roles: All employees, HR/Recruiting, Procurement/Contracts, Sales/Business development, Executives and assistants, Government relations, IT/Security (patch management).
  • Affected industries: Non-governmental organizations (NGOs), Mining, Physical commodity trading, Aerospace/defense, Manufacturing, Government, Consulting/Professional services, Finance/Financial services.
  • Attack channels: email, website.
  • Impersonated: University student / internship applicant, Procurement contact at a (spoofed) US aerospace company, Conference organizer / event registration team.

Red flags to watch for

  • Unexpected internship inquiry with an external link
  • Pressure to click a link rather than sending a standard resume/attachment through normal channels
  • Sender identity can’t be verified or does not match a real student/university
  • RFQ link goes to an unfamiliar or lookalike domain
  • Urgent procurement language pushing link-clicking rather than established vendor portals
  • Brand/company name in email doesn’t align with the domain hosting the RFQ
  • Conference invite arrives unexpectedly and pushes an external link
  • Event branding does not match the website domain or sender address
  • Unusual urgency or too-good-to-miss framing to drive immediate clicks
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the BlueMoon exploit kit?

BlueMoon is a shared exploit kit used by at least four suspected espionage groups that starts with a phishing email containing an attacker-controlled link, then chains browser and Windows vulnerabilities to install spyware.

How did BlueMoon infect victims?

Clicking a malicious link in a phishing email triggered two Chromium V8 issues plus a Windows privilege escalation bug (CVE-2026-85880), allowing attackers to run code and install payloads without further user action.

What lures were used in the BlueMoon campaigns?

Campaigns used tailored pretexts including internship inquiries to HR, defense-industry requests for quotation, and invitations to Indonesian conferences to get targets to click malicious links.

What did the fake Google Gemini extension do?

One campaign installed a malicious browser extension disguised as Google Gemini that stole cookies and other sensitive data, took screenshots, and injected a keylogger into a browser tab.

Read the video transcript

You get an email: “Hi, I’m a university student interested in internship opportunities… here’s my details at this link.” Looks harmless, right? Behind that click is BlueMoon, a exploit kit using fresh browser zero‑days and a Windows bug, CVE‑2026‑85880, to hijack your machine and drop a fake “Google Gemini” extension that spies on your tabs, cookies, and screenshots. Same play in defense RFQs: “Request for Quotation: review details using the link provided.” But the RFQ link goes to an odd lookalike aerospace domain that doesn’t match the brand in the email header. If an unsolicited email wants you to click a link to view internships, RFQs, or event details, stop. Don’t click, forward it to security and confirm through your usual trusted channel.

Similar attacks

ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

Researchers found multiple espionage groups using the same Chrome+Windows exploit kit (“BlueMoon”) within days of each other. The groups sent realistic phishing emails (internship requests, conference outreach, procurement inquiries, and vaccination appointments) that pushed victims to click links…

September 10, 2026
APT31 Phish Drops Fake “Gemini” Extension

APT31 Phish Drops Fake “Gemini” Extension

Multiple China-aligned espionage groups used phishing emails to deliver a “BlueMoon” exploit chain that abused three zero-day flaws in Chrome/Chromium and Windows. In observed campaigns, victims who clicked the phishing link ended up with a malicious browser extension disguised as Google Gemini,…

September 9, 2026
Spy Groups Lured Victims to BlueMoon Exploit Links

Spy Groups Lured Victims to BlueMoon Exploit Links

Proofpoint reports multiple espionage-focused threat groups used a shared exploit kit (“BlueMoon”) after tricking targets with spear-phishing emails to click malicious links. Visiting the attacker-controlled web pages triggered Chrome and Windows exploits to install malware (including a fake…

September 9, 2026
NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Russian Spy Phish Uses Legit OAuth Logins

Russian Spy Phish Uses Legit OAuth Logins

Google says three suspected Russian cyber-espionage groups are running highly targeted phishing campaigns against people in government, academia, defense, and think tanks in the US and Europe. A key theme is abusing legitimate Google/Microsoft OAuth login flows so the outreach looks real, tricking…

August 21, 2026