Skip to content
Tech News
← Back to articles

4 groups caught using the same Chrome and Windows exploit kit

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

A ready-made exploit chain dubbed BlueMoon strings together two Chromium bugs and a Windows kernel flaw to install arbitrary malware, and it's already circulating among at least four hacking groups, some linked to the Chinese government. The speed and sloppiness of its deployment suggest attackers were racing the 'patch gap' between public Chromium fixes and browser updates, possibly with AI assistance in finding bugs. That points to a future where full browser exploit chains are cheap and common rather than rare and precious.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — When browser and Windows zero-days are chained to drop malware, phishing-resistant hardware login is one of the few defenses that still holds up. The YubiKey 5 NFC plugs into USB-A or taps NFC phones and works with Google, Microsoft and password managers for strong two-factor sign-in.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government.

Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10, Windows 22, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours.

Deployed rapidly, widely shared

The attacks lacked the stealth found in many campaigns. More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.

Both these factors likely pushed the attackers to move quickly before a window of opportunity closed. Proofpoint said:

A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development. This is particularly relevant for open source codebases, such as Chromium, where upstream patches are publicly accessible prior to downstream consumers of the codebase applying the patch. This creates a window for threat actors to attempt to rapidly reverse engineer patches and develop exploits ahead of downstream stable releases.

The four groups targeted a wide range of organizations and companies. The groups and targets included: