🔍 Contexte

Publié le 8 septembre 2026 par l’équipe Threat Research de Proofpoint, en collaboration avec Google GTIG, Microsoft MSTIC et Volexity, ce rapport documente la découverte et l’adoption rapide du kit d’exploitation BlueMoon par plusieurs acteurs de menace alignés sur des États, principalement la Chine, entre fin août et début septembre 2026.

🧩 Description de BlueMoon

BlueMoon est un exploit kit chaînant trois vulnérabilités :

  • CVE-2026-85046 : confusion de type dans le moteur V8 de Chromium (RCE dans le renderer)
  • CVE-2026-87491 : échappement du sandbox V8 via corruption de métadonnées WebAssembly
  • CVE-2026-85880 : élévation de privilèges locale (LPE) dans le noyau Windows via ALPC/WNF, ciblant des builds Windows anciens (10 1809, 20H2, 21H2, 22H2, Server 2019/2022, Windows 11 21H2)

Les deux vulnérabilités V8 étaient des patch-gap zero-days : corrigées dans le code source Chromium upstream mais non encore déployées dans les versions stables publiques. Le LPE Windows présente un timestamp de compilation datant de 2025, suggérant une réutilisation d’une capacité existante.

🤖 Indicateurs de développement assisté par IA

Plusieurs artefacts suggèrent un développement assisté par IA : journalisation diagnostique extensive, commentaires documentant des itérations de débogage successives, référence à un fichier handover Markdown (docs/v8-ctf-chrome-stage4-handover.md), et références au programme v8CTF de Google. La configuration par défaut (téléchargement via curl et exécution directe) révèle une priorité donnée à la rapidité de déploiement sur la discrétion.

👥 Acteurs identifiés et campagnes

TA412 (JungleBamboo / APT31 / Violet Typhoon) — Chine-aligné, MSS/HSSD :

  • Première utilisation observée le 28 août 2026
  • Cibles : ONG, sociétés minières, négociants en matières premières aux États-Unis
  • Leurres : candidatures de stage, conférence AAS-in-Asia 2026
  • Payload : installateur d’extension malveillante GemStone déguisée en Google Gemini (surveillance navigateur, vol de credentials, keylogger)

UNK_LateNight — Chine-aligné (suspecté) :

  • Actif depuis le 2 septembre 2026
  • Cibles : entreprises aérospatiales américaines (thème B2B/RFQ défense)
  • Payload : backdoor ShadowPad via DLL-sideloading, tâche planifiée EdgeCore_AutoUpdate, C2 ms.checrity[.]com

UNK_DoubleCheck — Attribution pays non établie, espionnage suspecté :

  • Actif depuis le 2 septembre 2026
  • Cible : entité manufacturière vietnamienne, email compromis d’un gouvernement d’Asie du Sud-Est
  • Payload : chaîne DLL-sideloading avec loader Rust, C2 via Cloudflare R2 et fracons[.]com

UNK_QuietRacket — Chine-aligné (suspecté) :

  • Actif depuis le 3 septembre 2026
  • Cibles : gouvernement, conseil, finance en Indonésie et Singapour
  • Payload : DLL-sideloading avec résolution C2 via Google DNS-over-HTTPS (TXT records chiffrés ChaCha20), assembly .NET chargé en mémoire

🎯 Mécanisme de livraison commun

Tous les acteurs ont utilisé du spearphishing avec liens vers des domaines contrôlés hébergeant BlueMoon. L’infrastructure était créée le jour même ou dans les jours précédant les campagnes. La chaîne d’exploitation par défaut génère un arbre de processus distinctif : chrome.exe → cmd.exe → curl.exe → msgbox.exe.

📄 Type d’article

Rapport de recherche CTI à visée communautaire, publié par Proofpoint Threat Research, documentant une nouvelle capacité d’exploitation, ses variantes, les acteurs l’utilisant, et fournissant des indicateurs de compromission, règles YARA et règles ET pour la détection.

🧠 TTPs et IOCs détectés

Acteurs de menace

  • TA412 (state-sponsored) — orkl.eu · Malpedia
  • UNK_LateNight (state-sponsored) —
  • UNK_DoubleCheck (unknown) —
  • UNK_QuietRacket (state-sponsored) —

TTP

  • T1566.002 — Phishing: Spearphishing Link (Initial Access)
  • T1203 — Exploitation for Client Execution (Execution)
  • T1068 — Exploitation for Privilege Escalation (Privilege Escalation)
  • T1055 — Process Injection (Defense Evasion)
  • T1574.002 — Hijack Execution Flow: DLL Side-Loading (Defense Evasion)
  • T1059.003 — Command and Scripting Interpreter: Windows Command Shell (Execution)
  • T1105 — Ingress Tool Transfer (Command and Control)
  • T1176 — Browser Extensions (Persistence)
  • T1053.005 — Scheduled Task/Job: Scheduled Task (Persistence)
  • T1112 — Modify Registry (Defense Evasion)
  • T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
  • T1132.001 — Data Encoding: Standard Encoding (Command and Control)
  • T1041 — Exfiltration Over C2 Channel (Exfiltration)
  • T1056.001 — Input Capture: Keylogging (Collection)
  • T1539 — Steal Web Session Cookie (Credential Access)
  • T1113 — Screen Capture (Collection)
  • T1012 — Query Registry (Discovery)
  • T1082 — System Information Discovery (Discovery)
  • T1016 — System Network Configuration Discovery (Discovery)
  • T1562.001 — Impair Defenses: Disable or Modify Tools (Defense Evasion)
  • T1027 — Obfuscated Files or Information (Defense Evasion)
  • T1140 — Deobfuscate/Decode Files or Information (Defense Evasion)
  • T1608.001 — Stage Capabilities: Upload Malware (Resource Development)
  • T1583.001 — Acquire Infrastructure: Domains (Resource Development)

IOC

  • IPv4 : 79.133.56.90AbuseIPDB · VT · ThreatFox
  • Domaines : secboxes.comVT · URLhaus · ThreatFox
  • Domaines : msbenefit.comVT · URLhaus · ThreatFox
  • Domaines : attcdn.comVT · URLhaus · ThreatFox
  • Domaines : checrity.comVT · URLhaus · ThreatFox
  • Domaines : airproducts.inkVT · URLhaus · ThreatFox
  • Domaines : precipart.inkVT · URLhaus · ThreatFox
  • Domaines : epsilonsystems.netVT · URLhaus · ThreatFox
  • Domaines : rocketlabusa.inkVT · URLhaus · ThreatFox
  • Domaines : spectrolab.fitVT · URLhaus · ThreatFox
  • Domaines : aurexdefense.onlineVT · URLhaus · ThreatFox
  • Domaines : cyclokinetics.onlineVT · URLhaus · ThreatFox
  • Domaines : sncorp.fitVT · URLhaus · ThreatFox
  • Domaines : tcomlp.onlineVT · URLhaus · ThreatFox
  • Domaines : bosch-sensortec.siteVT · URLhaus · ThreatFox
  • Domaines : smxtech.xyzVT · URLhaus · ThreatFox
  • Domaines : lindes.inkVT · URLhaus · ThreatFox
  • Domaines : silvustechnologies.onlineVT · URLhaus · ThreatFox
  • Domaines : worldview.fitVT · URLhaus · ThreatFox
  • Domaines : emcore.inkVT · URLhaus · ThreatFox
  • Domaines : airindia.fitVT · URLhaus · ThreatFox
  • Domaines : airliquide.lolVT · URLhaus · ThreatFox
  • Domaines : apollohospitals.fitVT · URLhaus · ThreatFox
  • Domaines : haloengines.netVT · URLhaus · ThreatFox
  • Domaines : jetoptera.coVT · URLhaus · ThreatFox
  • Domaines : joinmacket.comVT · URLhaus · ThreatFox
  • Domaines : openlumakora.comVT · URLhaus · ThreatFox
  • Domaines : getaiexo.comVT · URLhaus · ThreatFox
  • Domaines : elixnovorem.comVT · URLhaus · ThreatFox
  • Domaines : velodynaity.comVT · URLhaus · ThreatFox
  • Domaines : brianwilli.comVT · URLhaus · ThreatFox
  • Domaines : fracons.comVT · URLhaus · ThreatFox
  • URLs : https://project.secboxes.com/ChromeUpdate.exeURLhaus
  • URLs : https://recommendation-letter.secboxes.com/ChromeUpdate.exeURLhaus
  • URLs : https://download.secboxes.com:443/dist.zipURLhaus
  • URLs : https://api-prod.secboxes.com:443/downloadURLhaus
  • URLs : https://evidence.msbenefit.com/msgbox.exeURLhaus
  • URLs : https://zki0y83.msbenefit.com:443/feedURLhaus
  • URLs : https://app.eduac.workers.dev/ServiceURLhaus
  • URLs : https://app.eduac.workers.dev/UpdateacURLhaus
  • URLs : https://small-union-7018.daoahueb.workers.dev/URLhaus
  • URLs : https://snowy-block-ae0a.daoahueb.workers.dev/URLhaus
  • URLs : https://homepage.brianwilli.com/d/calibre-launcher.dllURLhaus
  • URLs : https://homepage.brianwilli.com/d/wint.exeURLhaus
  • URLs : https://homepage.brianwilli.com/d/85rY.datURLhaus
  • URLs : https://homepage.brianwilli.com/d/SysPr.prxURLhaus
  • URLs : https://1a062f4982564d6d19a76884ce8bcbb6.r2.cloudflarestorage.com/datago/krita.exeURLhaus
  • URLs : https://1a062f4982564d6d19a76884ce8bcbb6.r2.cloudflarestorage.com/datago/krita.dllURLhaus
  • URLs : https://1a062f4982564d6d19a76884ce8bcbb6.r2.cloudflarestorage.com/datago/SysPr.prxURLhaus
  • URLs : https://api.ipify.org?format=jsonURLhaus
  • URLs : https://ipinfo.io/jsonURLhaus
  • SHA256 : 779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096dVT · MalwareBazaar
  • SHA256 : ff1b49aaec994f4c11f2c9331e739abb4bc3d6abf66ec50ce99709fba35d782bVT · MalwareBazaar
  • SHA256 : 7d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288VT · MalwareBazaar
  • SHA256 : e950d03c58d49e28e31df8afeefca1f3b3d2cd6b697c40adfee1a4f6fe18f004VT · MalwareBazaar
  • SHA256 : 353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98eeVT · MalwareBazaar
  • SHA256 : a4a6a04d85eca8d584d939d2437c85a4f291207d8042f2ec002838e336b72ef5VT · MalwareBazaar
  • SHA256 : 295fc584f75e94108c9be945977db33ed80421f5d374eab188587c911dffd915VT · MalwareBazaar
  • SHA256 : bc7d24f5cf8937b334966201bdcce8ca9bab6ec5889d40a399d4094dcad73360VT · MalwareBazaar
  • SHA256 : b34802a646fc4a8f07ffa09a5fda8bf7327446b22e3d7bb5163dafa1e2a8bb2bVT · MalwareBazaar
  • SHA256 : 8453c42904b7b2fea5671b7bff06b2d937632ae29545fd11bc13095627a2805fVT · MalwareBazaar
  • SHA256 : f3c64014221a58f3fde88e562662dbd5a1b3dd2b59c86e9e2bc5cb8f671664e7VT · MalwareBazaar
  • SHA256 : 87b6b24c06f99900a8aa579caedee1e402015884c925a98dcfb0fb38dfa2de22VT · MalwareBazaar
  • SHA256 : ac6bbc4b1f1c62e308781329183a46e18f454c27e66bffa09f343b53ac622b69VT · MalwareBazaar
  • SHA256 : ac6806c89e294f390838cb07c015dabec1c8ada06ce5161a0ad50b8a72828141VT · MalwareBazaar
  • SHA256 : 3594ad58fb6217fafe9839e53999a90608c2e9f335fa20aece3d53f8c0802726VT · MalwareBazaar
  • SHA256 : 3ec3151d8d1278ed966941ac89ea495ef6a80c70613dd9138cc85fc28c9df432VT · MalwareBazaar
  • SHA256 : 6e6378d8d404166da89d982e80bc52e19a3f677201258dec1775f100a027a92dVT · MalwareBazaar
  • Emails : zfg.rc.420@gmail.com
  • Emails : laylowthiago@gmail.com
  • Emails : susan.thomas.90@outlook.com
  • Emails : mariedubois1917@outlook.com
  • Emails : reallifetalktv2@gmail.com
  • Emails : faizus123@outlook.com
  • Emails : firda.kemkes@outlook.com
  • Emails : faizus123@proton.me
  • Emails : dewiinpermata@outlook.com
  • Emails : radhikadas07@outlook.com
  • Emails : jeannifer.suryajaya@outlook.com
  • Emails : siti.nurhaliza2026@outlook.com
  • Emails : ditjenpajakri2026@outlook.com
  • CVEs : CVE-2026-85046NVD · CIRCL
  • CVEs : CVE-2026-87491NVD · CIRCL
  • CVEs : CVE-2026-85880NVD · CIRCL
  • Fichiers : driver-html.js
  • Fichiers : ChromeUpdate.exe
  • Fichiers : msgbox.exe
  • Fichiers : dist.zip
  • Fichiers : background.js
  • Fichiers : Index.js
  • Fichiers : mctsetup64.dll
  • Fichiers : Loader.js
  • Fichiers : Indostartupexpo.js
  • Fichiers : GFExperienceUpdate.dll
  • Fichiers : GfExperienceService64.exe
  • Fichiers : font-01.js
  • Fichiers : calibre-launcher.dll
  • Fichiers : SysPr.prx
  • Fichiers : krita.dll
  • Fichiers : wint.exe
  • Fichiers : 85rY.dat
  • Fichiers : A08744D2.tmp
  • Fichiers : krita.exe
  • Chemins : C:\Users\Public\stomp_ext
  • Chemins : %APPDATA%\Microsoft\Windows\wint.exe
  • Chemins : C:\ProgramData\GfExperienceService64.exe
  • Chemins : HKCU\SOFTWARE\Classes\CLSID\{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32

⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 10 septembre 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.

Malware / Outils

  • BlueMoon (framework)
  • GemStone (backdoor)
  • ShadowPad (backdoor)
  • SysPr.prx Rust loader (loader)
  • calibre-launcher.dll (loader)
  • mctsetup64.dll (loader)

🟢 Indice de vérification factuelle : 100/100 (haute)

  • ✅ proofpoint.com — source reconnue (liste interne) (20pts)
  • ✅ 43744 chars — texte complet (fulltext extrait) (15pts)
  • ✅ 107 IOCs dont des hashes (15pts)
  • ✅ 5/10 IOCs confirmés (AbuseIPDB, MalwareBazaar, ThreatFox, URLhaus, VirusTotal) (15pts)
  • ✅ 24 TTPs MITRE identifiées (15pts)
  • ✅ date extraite du HTML source (10pts)
  • ✅ acteur(s) identifié(s) : TA412, UNK_LateNight, UNK_DoubleCheck (5pts)
  • ✅ 3/3 CVE(s) confirmée(s) (CIRCL) (5pts)

IOCs confirmés externellement :

  • 79.133.56.90 (ip) → VT (3/89 détections)
  • 7d6f6dcb17a423bd… (sha256) → VT (12/76 détections)
  • secboxes.com (domain) → VT (9/89 détections)
  • msbenefit.com (domain) → VT (10/89 détections)
  • attcdn.com (domain) → VT (7/89 détections)

🔗 Source originale : https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit