Security/ security · chrome · windows · exploit-kits

Four Hacking Groups Share One Chrome and Windows Exploit Kit

BlueMoon chains three now-patched Chrome and Windows bugs, and four hacking groups, some tied to China, are all using it.

A single exploit kit dubbed BlueMoon is now confirmed in use by four separate hacking groups, including some with ties to Beijing.

Security firm Proofpoint said this week that BlueMoon chains together three vulnerabilities, two in Chromium-based browsers and one in the Windows kernel, to let attackers install whatever malware they choose. The kernel flaw affects a wide swath of older Windows builds, including Windows 10's October 2018 Update, Windows Server 2019, Windows 10 2004, Windows Server 2022, and the original Windows 11 release. All three bugs got patches within the last 24 hours. Unlike most exploit chains, which stay quiet to extend their shelf life, BlueMoon has been deployed loudly and widely.

Proofpoint points to two likely reasons for the lack of stealth. One is a patch gap in the Chromium supply chain, the delay between when a fix ships and when it actually reaches Chrome and Edge users. The other is AI-assisted vulnerability research, which can spot exploitable bugs faster than a team of humans combing through code by hand.

Four unrelated groups landing on the same exploit chain in the same narrow window is less a coincidence than a sign that finding and sharing these bugs is getting easier, patch or no patch.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →