4 Groups Caught Using the Same Chrome and Windows Exploit Kit
Proofpoint said the kit chains three flaws to install malware and was shared across at least four hacking groups within days.
- Security firm Proofpoint identified a new exploit kit named BlueMoon that chains three zero-day vulnerabilities to target Chrome, Chromium-based browsers, and Microsoft Windows, with at least four state-aligned groups deploying it since late August.
- Attackers exploited a "patch gap" between upstream Chromium fixes and downstream browser updates, allowing threat actors to develop and deploy exploits rapidly before public patches became available to users.
- Beijing-Backed group TA412, also known as Violet Typhoon or APT31, used BlueMoon to "repeatedly" target NGOs and mining firms; other China-aligned clusters also deployed the kit against aerospace and manufacturing firms in Indonesia and Singapore.
- Infected victims encountered loaders installing malicious extensions like GemStone, enabling spies to steal cookies, take screenshots, and inject keyloggers; some attacks deployed ShadowPad backdoors to maintain access.
- All three vulnerabilities received patches within the past 24 hours, mitigating immediate threats, though Proofpoint warns the low barrier to entry means BlueMoon or similar kits will likely see adoption by other attackers soon.
8 Articles
8 Articles
A new exploit kit called BlueMoon combines two Chromium-based browser bugs with a Windows vulnerability to attack organizations in the United States and Southeast Asia. Proofpoint researchers link their initial use with spy groups related to China and warn that artificial intelligence may be reducing the cost of developing previously reserved attack chains for high-value operations.
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker - National Cyber Security Consulting
At least four cyber-espionage groups, most linked to Chinese state intelligence, have been using the same previously unknown Google Chrome vulnerability in attacks beginning late August and continuing into this week, cybersecurity firm Proofpoint said Wednesday. The groups were observed using the same exploit kit, dubbed BlueMoon by Proofpoint, to compromise Chrome browsers and deploy malware […] Thank you for subscribing to our RSS feed!
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium





