Four groups caught using the same Chrome and Windows exploit kit

by | Sep 28, 2026 | Technology

Four groups caught using the same Chrome and Windows exploit kit

Researchers at Proofpoint identified BlueMoon, an exploit kit being deployed by at least four hacking groups with some connections to Chinese government entities. The kit chains together three vulnerabilities—two in Chromium-based browsers and one in Windows kernels—allowing attackers to install malware of their choice on compromised systems.

The affected Windows versions include Windows 10 (Oct. 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities received patches within 24 hours of the Proofpoint disclosure. The two Chromium vulnerabilities reside in V8, Google’s JavaScript engine, with one involving a type confusion bug and the other a sandbox escape. The Windows vulnerability enables local privilege escalation, allowing malicious code to execute with system-level permissions.

SecurityResearchers attribute the rapid deployment and wide sharing of BlueMoon across multiple threat actors to two primary factors: a “patch gap” in the Chromium supply chain that creates a window between when developers release patches and when those patches are incorporated into public browser releases, and the accelerating pace of AI-based vulnerability discovery. The visible nature of these attacks, which typically contradicts standard hacking practices that favor stealth, further suggests attackers felt pressured to move quickly before patches closed their exploitation window.

Attacks began as early as August 28 and continued earlier this month, targeting diverse organizations across multiple sectors. The initial campaign came from TA412, with additional campaigns attributed to other groups. Proofpoint cautioned that despite patches being available and detection signals being high, BlueMoon may continue circulating. The researchers warned that the kit’s ease of adoption could lead to broader proliferation among both espionage-motivated and financially motivated threat actors as patched versions roll out across Chromium-based browsers.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI