Skip to content
Tech News
← Back to articles

Four groups caught using the same Chrome and Windows exploit kit

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

An exploit kit dubbed BlueMoon chains three vulnerabilities in Chromium browsers and the Windows kernel, and it's already being used by at least four hacking groups, some linked to the Chinese government. What's notable is the speed and lack of stealth: researchers suspect attackers exploited the public 'patch gap' in Chromium's open source supply chain and may have used AI to accelerate exploit development, suggesting full browser exploit chains are getting cheaper and easier to build.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — When browser exploit chains can drop malware and steal session cookies, hardware-backed sign-in is one of the few defenses that still holds up. The YubiKey 5 NFC plugs into USB-A or taps on your phone for phishing-resistant two-factor login across Google, Microsoft and password managers. It's a simple, tangible upgrade for anyone rattled by news of shared zero-day kits.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at least four hacking groups, some of which have ties to the Chinese government.

Researchers from security firm Proofpoint said Wednesday that BlueMoon, the name they gave to the kit, chains three vulnerabilities together so the attackers using it can install malware of their choice. BlueMoon exploits two Chromium vulnerabilities and one in the kernel of Windows 10 (Oct. 2018 Update), Windows Server 2019, Windows 10 2004, Windows Server 2022, and the initial release of Windows 11. All three vulnerabilities have received patches in the past 24 hours.

Deployed rapidly, widely shared

The attacks lacked the stealth found in many campaigns. More often, hackers want to exploit newly discovered vulnerabilities sparingly to lengthen their longevity. Proofpoint hypothesized that one reason for the widely used and visible exploit chain was to take advantage of a “patch gap” in the Chromium supply chain, which spans the time a patch is available from developers and the time that patch is incorporated into browsers such as Chrome and Edge. Another likely contributor was the use of AI, which can often spot vulnerabilities faster than discovery performed solely by humans.

Both these factors likely pushed the attackers to move quickly before a window of opportunity closed. Proofpoint said:

A fully weaponized Chrome exploit chain has historically been a high-value, rare capability. BlueMoon was developed, deployed rapidly, and shared across multiple threat actors within days in a manner that had high detection signals. This may reflect a reduced cost and barrier to entry for this class of capability, as AI agents increasingly enable threat actor exploit development. This is particularly relevant for open source codebases, such as Chromium, where upstream patches are publicly accessible prior to downstream consumers of the codebase applying the patch. This creates a window for threat actors to attempt to rapidly reverse engineer patches and develop exploits ahead of downstream stable releases.

The four groups targeted a wide range of organizations and companies. The groups and targets included: