Four groups caught using the same Chrome and Windows exploit kit

by | Oct 8, 2026 | Technology

Four groups caught using the same Chrome and Windows exploit kit

Security researchers at Proofpoint disclosed the discovery of BlueMoon, an exploit kit being actively used by at least four hacking groups to compromise systems running Chromium-based browsers and vulnerable versions of Windows. Some of the groups operating the kit have reported ties to the Chinese government. The toolkit chains three separate vulnerabilities together, allowing attackers to deploy malware of their choosing on compromised systems.

The three vulnerabilities exploited by BlueMoon include two flaws in Chromium’s V8 JavaScript engine and one privilege escalation weakness in the Windows kernel affecting Windows 10, Windows Server 2019, Windows Server 2022, and Windows 11. All three vulnerabilities received patches within the past 24 hours of Proofpoint’s announcement. The attack activity began on August 28 with one group, while the remaining three groups launched campaigns earlier this month.

Researchers noted that the exploit kit’s widespread adoption and visible deployment diverged from typical hacking practices, where newly discovered vulnerabilities are usually deployed sparingly to extend their operational window. Proofpoint attributed this aggressive approach to two primary factors: attackers attempting to exploit a “patch gap” in Chromium’s supply chain—the interval between patch release and integration into stable browser versions—and the increasing capability of AI systems to identify vulnerabilities more rapidly than traditional human-led discovery methods.

Proofpoint highlighted that the rapid development and dissemination of a fully weaponized Chrome exploit chain across multiple threat actors within days suggested a declining barrier to entry for such capabilities, driven by AI-assisted exploit development. The researchers noted that open-source codebases like Chromium created particular vulnerability windows, since upstream patches are publicly accessible before downstream consumers like Chrome and Edge incorporate them, providing attackers time to reverse-engineer patches and develop exploits.

Despite patches now being available for all three vulnerabilities and BlueMoon’s visible operational footprint, Proofpoint cautioned that the toolkit may continue proliferating among both espionage-motivated and financially motivated threat actors as patched browser versions roll out across organizations.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI