Four Hacking Groups Exploit BlueMoon Kit Targeting Chrome and Windows Vulnerabilities

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government. Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours.

Deployed Rapidly, Widely Shared

The attacks lacked the stealth found in many campaigns. More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.

Both these factors likely pushed the attackers to move quickly before a window of opportunity closed. Proofpoint noted that a fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development. This is particularly relevant for open source codebases, such as Chromium, where upstream patches are publicly accessible prior to downstream consumers of the codebase applying the patch. This creates a window for threat actors to attempt to rapidly reverse engineer patches and develop exploits ahead of downstream stable releases.

The four groups targeted a wide range of organizations and companies.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

L3Harris awarded contract for VAMPIRE counter-drone system delivery

L3Harris Technologies has been awarded a contract to deliver its VAMPIRE (Vehicle-Agnostic Modular Palletized ISR Rocket Equipment) counter-unmanned system to the U.S. Navy for...

CWME_REVIEW_REQUIRED

Eruptions are a regular occurrence at Anak Krakatau, a small volcano located between the Indonesian islands of Java and Sumatra. While much of its...

Cybercriminals Exploit Infostealer Logs to Bypass MFA with Stolen AI Tokens

Cybercriminals are increasingly exploiting information stealer logs to hijack artificial intelligence (AI) user accounts, creating "stolen keys" that provide unauthorized access to tools from...

CISA Warns of Exploited Microsoft Vulnerabilities as Patch Tuesday Discloses Record 973 Bugs

Microsoft's latest Patch Tuesday release has set a new record, disclosing 973 vulnerabilities, with two of them—CVE-2026-81963 and CVE-2026-85880—actively exploited by hackers, according to...