BlueMoon Chained Chrome and Windows Zero-Days Across Multiple Espionage Campaigns
5 Articles
5 Articles
BlueMoon chained Chrome and Windows zero-days across multiple espionage campaigns
Researchers observed the modular BlueMoon exploit kit in attacks from at least four clusters, including JungleBamboo and UTA0560. The chain combined two Chromium flaws for code execution and sandbox escape with a Windows ALPC local privilege...
An almost identical attack kit, capable of hitting Chrome in sequence, the Chromium-based browsers and some old versions of Windows, ended up in the hands of at least four hacker groups, some of them related to the Chinese government. The BlueMoon exploit kit, so named by Proofpoint researchers, allowed attackers to install [...]
BlueMoon exploit kit spreads to four hacking groups within days
A single piece of attack code, quietly built to chain three unpatched flaws in Chrome and Windows, has ended up in the hands of at least four separate hacking crews within days of each other. Researchers at cybersecurity firm Proofpoint have named it BlueMoon exploit kit , and they say it’s already...
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days Pierluigi Paganini September 10, 2026 Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly
Coverage Details
Bias Distribution
- 100% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium




