Four groups caught using the same Chrome and Windows exploit kit

by | Sep 24, 2026 | Technology

Four groups caught using the same Chrome and Windows exploit kit

Security researchers at Proofpoint identified an exploit kit designated BlueMoon that chains together multiple vulnerabilities affecting Chromium-based browsers and Windows systems. The kit exploits two vulnerabilities in Google’s V8 JavaScript engine and one Windows kernel flaw, allowing attackers to install malware with system-level privileges. The affected Windows versions include the October 2018 Update of Windows 10, Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. Patches for all three vulnerabilities were released within the past 24 hours.

At least four separate hacking groups have deployed BlueMoon, with some demonstrating ties to Chinese government entities. The first confirmed attacks began on August 28, with additional campaigns occurring earlier in September. The toolkit has been used against a wide range of targets across different organizations and sectors. Researchers noted that the exploit kit was developed and deployed rapidly, then shared among multiple threat actors within days, exhibiting characteristics inconsistent with typical high-value exploit campaigns that are usually kept covert to maximize effectiveness.

Proofpoint identified two key factors driving the accelerated deployment and widespread adoption of the kit. A “patch gap” in the Chromium supply chain creates a window between when patches are released by developers and when they are incorporated into stable browser releases available to users. Additionally, the involvement of artificial intelligence in vulnerability discovery likely enabled faster identification and weaponization of the flaws compared to traditional human-led research methods. Both factors pressured attackers to move quickly before patches reached end users and closed the exploitation window.

The two V8 vulnerabilities exploited by BlueMoon involved a type confusion bug and a sandbox escape mechanism, enabling remote code execution. The Windows privilege escalation flaw allowed the malicious code to operate with system-level permissions. Both V8 vulnerabilities were classified as “patch-gap zero-days,” meaning they were already publicly fixed in upstream Chromium source code but remained unpatched in public stable browser releases at the time of exploitation. Researchers indicated the exploit kit developer likely leveraged these publicly available patches to develop the weaponized chain.

Despite widespread detection signals and the availability of patches, Proofpoint cautioned that BlueMoon may continue circulating among threat actors. The kit’s accessibility and ease of adoption increase the likelihood of further proliferation as patched versions gradually roll out across Chromium-based browsers, potentially attracting both espionage-focused and financially motivated groups.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI