Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
AI Generated Image

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

The Hacker News technology

Key Points:

  • Multiple espionage groups, primarily China-aligned, have deployed a new exploit kit called BlueMoon that chains vulnerabilities in Microsoft Windows and Google Chrome to achieve remote code execution and privilege escalation.
  • BlueMoon exploits three vulnerabilities: two zero-day type confusion and sandbox escape flaws in Chrome's V8 engine, and a heap-based buffer overflow in Windows ALPC; the Chrome flaws were "patch-gap" zero-days exploited before stable browser updates were released.
  • The exploit kit is delivered via spear-phishing emails leading victims to malicious URLs that trigger the chained exploits, followed by downloading payloads such as backdoors, loaders, and DLL sideloading malware tailored to specific threat actor campaigns.
  • APT31 and several other espionage clusters have used BlueMoon since late August 2026 to target NGOs, aerospace, manufacturing, government, and financial sectors across the U.S., Vietnam, Indonesia, and Singapore.
  • Proofpoint notes the exploit kit’s development may have been aided by AI tools, reflecting a lowering of barriers for sophisticated exploit creation, and warns that patched browsers prevent new infections but do not remove persistent malware already installed; detection indicators and mitigation guidance have been published.

Trending Business

Trending Technology

Trending Health