Four groups caught using the same Chrome and Windows exploit kit

by | Sep 13, 2026 | Technology

Four groups caught using the same Chrome and Windows exploit kit

Security researchers at Proofpoint identified an exploit kit dubbed BlueMoon being actively deployed by at least four hacking groups to target critical vulnerabilities in Chromium-based browsers and older Windows operating systems. The kit chains three vulnerabilities together, allowing attackers to install malware of their choice on compromised systems.

The three exploited vulnerabilities affect Windows 10, Windows Server 2019, Windows 10 2004, Windows Server 2022, and Windows 11, along with Chromium-based browsers. All three vulnerabilities have received patches. The attack methodology involved exploiting two Chromium vulnerabilities within V8, Google’s JavaScript engine, followed by leveraging a local privilege escalation vulnerability in older Windows versions to execute code with system-level permissions. The Chromium vulnerabilities were classified as “patch-gap” zero-days, meaning patches existed in public upstream source code but had not yet been incorporated into stable public browser releases.

Researchers identified multiple factors contributing to the rapid development and widespread deployment of BlueMoon. A significant gap exists between when patches are available from developers and when those patches are integrated into browsers like Chrome and Edge, creating a window of vulnerability. Additionally, the role of artificial intelligence in vulnerability discovery may have accelerated the development process, as AI systems can identify security flaws more quickly than human-only analysis. These factors likely motivated the threat actors to move rapidly before exploitation opportunities closed.

The four groups utilizing BlueMoon began attacks starting August 28 and continuing into early September, targeting a wide range of organizations and companies. Some of these groups maintain alleged ties to Chinese government interests. Unlike typical high-value exploits that are used sparingly to extend their operational lifespan, BlueMoon was developed, deployed, and shared across multiple threat actors within days, exhibiting high detection signals.

Proofpoint researchers indicated that despite the visible nature of the campaign and the availability of patches, the exploit kit may continue proliferation. The researchers noted that ease of adoption suggests the kit could be further distributed among both espionage-focused and financially motivated threat actors as patched versions roll out across Chromium-based browsers.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI