BlueMoon exploit kit chains Chrome and Windows zero-days in espionage campaigns
Security researchers at Proofpoint and Volexity uncovered a modular attack tool called BlueMoon that strings together two Chromium browser flaws and a Windows kernel bug to achieve remote code execution and system-level control. The kit has been used since late August by China-linked group JungleBamboo (also known as APT31) and by a separate actor Volexity calls UTA0560, which targeted NGO staff. Analysts believe one of the three vulnerabilities, a Windows ALPC flaw, was repurposed from an existing 2025 exploit rather than newly built.